CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
110,849 results Clear all
CVE-2016-4851 6.1 MEDIUM EPSS 0.00
Let's Php! Simple Chat - XSS
Cross-site scripting (XSS) vulnerability in Let's PHP! simple chat before 2016-08-15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 02, 2016
CVE-2016-4848 6.1 MEDIUM EPSS 0.00
Clip-bucket Clipbucket < 2.8.1 - XSS
Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 02, 2016
CVE-2016-6376 6.5 MEDIUM EPSS 0.00
Cisco Wireless LAN Controller <8.3.102.0 - DoS
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device restart) via a malformed wIPS packet, aka Bug ID CSCuz40263.
CWE-399 Sep 02, 2016
CVE-2016-1471 6.1 MEDIUM EPSS 0.00
Cisco Small Business 220 <1.0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232.
CWE-79 Sep 02, 2016
CVE-2016-6298 5.3 MEDIUM EPSS 0.00
RSA <0.3.2 - Info Disclosure
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
CWE-200 Sep 01, 2016
CVE-2016-5047 6.5 MEDIUM EPSS 0.01
Netapp Oncommand System Manager - Denial of Service
NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.
Sep 01, 2016
CVE-2016-3010 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3005.
CWE-79 Sep 01, 2016
CVE-2016-3008 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-2956.
CWE-79 Sep 01, 2016
CVE-2016-3005 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3010.
CWE-79 Sep 01, 2016
CVE-2016-2997 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-3005, and CVE-2016-3010.
CWE-79 Sep 01, 2016
CVE-2016-2995 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2997, CVE-2016-3005, and CVE-2016-3010.
CWE-79 Sep 01, 2016
CVE-2016-2956 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-3008.
CWE-79 Sep 01, 2016
CVE-2016-2954 5.4 MEDIUM EPSS 0.00
IBM Connections - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008.
CWE-79 Sep 01, 2016
CVE-2016-3064 6.5 MEDIUM EPSS 0.00
Netapp Clustered Data Ontap < 8.2.4 - Information Disclosure
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.
CWE-200 Sep 01, 2016
CVE-2016-0293 6.1 MEDIUM EPSS 0.00
IBM BigFix <9.1.8, <9.2.8 - XSS
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.
CWE-79 Sep 01, 2016
CVE-2016-7119 5.4 MEDIUM EPSS 0.00
Dotnetnuke < 08.00.04 - XSS
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
CWE-79 Aug 31, 2016
CVE-2016-7118 5.5 MEDIUM EPSS 0.00
Debian Linux - NULL Pointer Dereference
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.
CWE-476 Aug 31, 2016
CVE-2016-5332 5.3 MEDIUM EPSS 0.00
Vmware Vrealize Log Insight - Path Traversal
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
CWE-22 Aug 31, 2016
CVE-2016-0397 5.9 MEDIUM EPSS 0.00
IBM BigFix <9.5.2 - Info Disclosure
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
CWE-200 Aug 30, 2016
CVE-2016-0292 5.5 MEDIUM EPSS 0.00
IBM BigFix <9.5.2 - Info Disclosure
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report.
CWE-200 Aug 30, 2016