CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
110,849 results Clear all
CVE-2016-5721 6.1 MEDIUM EPSS 0.00
Zimbra Collaboration <8.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 29, 2016
CVE-2015-5399 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
PHPVibe <4.21 - XSS
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.
CWE-79 Aug 26, 2016
CVE-2016-5664 4.3 MEDIUM EPSS 0.00
Accellion Kiteworks <kw2016.03.00 - Path Traversal
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.
CWE-22 Aug 26, 2016
CVE-2016-5663 6.1 MEDIUM EPSS 0.00
Accellion Kiteworks <kw2016.03.00 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote attackers to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) error_description parameter.
CWE-79 Aug 26, 2016
CVE-2016-1497 4.9 MEDIUM EPSS 0.00
F5 BIG-IP <11.2.1 HF16, 11.3.x, 11.4.x <11.4.1 HF10, 11.5.x <11.5.4...
The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager (APM) access logs via unspecified vectors.
CWE-200 Aug 26, 2016
CVE-2016-4655 5.5 MEDIUM KEV RANSOMWARE 4 PoCs Analysis EPSS 0.82
WebKit not_number defineProperties UAF
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
Aug 25, 2016
CVE-2016-6231 5.9 MEDIUM EPSS 0.00
Kaspersky Safe Browser iOS <1.7.0 - Info Disclosure
Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
CWE-200 Aug 25, 2016
CVE-2016-6365 6.1 MEDIUM EPSS 0.00
Cisco Firepower Management Center <5.4.0 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
CWE-79 Aug 23, 2016
CVE-2016-1477 6.5 MEDIUM EPSS 0.00
Cisco Connected Streaming Analytics 1.1.1 - Info Disclosure
Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pages, aka Bug ID CSCuz92891.
CWE-200 Aug 23, 2016
CVE-2016-6363 6.5 MEDIUM EPSS 0.01
Cisco Aironet <8.2.121.0-8.3.102.0 - DoS
The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via crafted 802.11 frames, aka Bug ID CSCva06192.
CWE-119 Aug 22, 2016
CVE-2016-6361 6.5 MEDIUM EPSS 0.01
Cisco Aironet <8.2.121.0-8.3.102.0 - DoS
The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via a crafted AMPDU header, aka Bug ID CSCuz56288.
CWE-20 Aug 22, 2016
CVE-2016-6359 6.1 MEDIUM EPSS 0.00
Cisco Transport Gateway <4.1(4.0) - XSS
Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug IDs CSCva40650 and CSCva40817.
CWE-79 Aug 22, 2016
CVE-2016-4376 6.5 MEDIUM EPSS 0.00
HPE FOS <7.4.1d, <8.0.1 - Info Disclosure
HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B switches allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-254 Aug 22, 2016
CVE-2016-1485 6.1 MEDIUM EPSS 0.00
Cisco Identity Services Engine <1.3(0.876) - XSS
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497.
CWE-79 Aug 22, 2016
CVE-2016-1476 5.4 MEDIUM EPSS 0.00
Cisco IP Phone 8800 <11.0 - XSS
Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCuz03024.
CWE-79 Aug 22, 2016
CVE-2016-6320 5.4 MEDIUM EPSS 0.00
Foreman <1.12.2 - XSS
Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.
CWE-79 Aug 19, 2016
CVE-2016-6319 6.1 MEDIUM EPSS 0.01
Foreman <1.12.2 - XSS
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter.
CWE-79 Aug 19, 2016
CVE-2016-5390 5.3 MEDIUM EPSS 0.00
Foreman < 1.11.4 - Information Disclosure
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
CWE-200 Aug 19, 2016
CVE-2016-4995 5.3 MEDIUM EPSS 0.00
Foreman < 1.11.4 - Information Disclosure
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
CWE-200 Aug 19, 2016
CVE-2016-4451 5.0 MEDIUM EPSS 0.00
Foreman < 1.11.2 - Security Feature Bypass
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
CWE-254 Aug 19, 2016