CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
110,849 results Clear all
CVE-2016-5878 6.8 MEDIUM EPSS 0.00
IBM FileNet Workplace <4.0.2.14 - Open Redirect
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CWE-601 Aug 08, 2016
CVE-2016-5331 6.1 MEDIUM EPSS 0.00
VMware vCenter Server <6.0 - Code Injection
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CWE-93 Aug 08, 2016
CVE-2016-3059 6.2 MEDIUM EPSS 0.00
IBM Tivoli Storage Flashcopy Manager ... - Information Disclosure
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
CWE-200 Aug 08, 2016
CVE-2016-3054 5.4 MEDIUM EPSS 0.00
IBM Filenet Workplace - XSS
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
CWE-79 Aug 08, 2016
CVE-2016-2989 6.5 MEDIUM EPSS 0.00
IBM Connections Portlets - Improper Access Control
Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CWE-284 Aug 08, 2016
CVE-2016-2925 5.4 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Aug 08, 2016
CVE-2016-2914 5.4 MEDIUM EPSS 0.01
IBM Engineering Lifecycle Optimizatio... - Unrestricted File Upload
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.
CWE-434 Aug 08, 2016
CVE-2016-2912 5.4 MEDIUM EPSS 0.00
IBM Engineering Lifecycle Optimization - Publishing - XSS
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Aug 08, 2016
CVE-2016-0361 6.5 MEDIUM EPSS 0.00
IBM GPFS <3.5.0.29-4.1.1.4 - Info Disclosure
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
Aug 08, 2016
CVE-2016-0280 5.4 MEDIUM EPSS 0.00
IBM Information Server <9.1.2.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Aug 08, 2016
CVE-2016-1474 4.3 MEDIUM EPSS 0.00
Cisco Prime Infrastructure 2.2(2) - XSS
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.
CWE-284 Aug 08, 2016
CVE-2016-6634 6.1 MEDIUM EPSS 0.01
WordPress <4.5 - XSS
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 07, 2016
CVE-2016-5359 5.9 MEDIUM EPSS 0.00
Wireshark - Memory Corruption
epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.
CWE-119 Aug 07, 2016
CVE-2016-5358 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-20 Aug 07, 2016
CVE-2016-5357 5.9 MEDIUM EPSS 0.01
Wireshark - Improper Input Validation
wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
CWE-20 Aug 07, 2016
CVE-2016-5356 5.9 MEDIUM EPSS 0.01
Wireshark - Memory Corruption
wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
CWE-119 Aug 07, 2016
CVE-2016-5355 5.9 MEDIUM EPSS 0.01
Wireshark - Improper Input Validation
wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
CWE-20 Aug 07, 2016
CVE-2016-5354 5.9 MEDIUM EPSS 0.00
Wireshark - NULL Pointer Dereference
The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-476 Aug 07, 2016
CVE-2016-5353 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-20 Aug 07, 2016
CVE-2016-5352 5.9 MEDIUM EPSS 0.00
Wireshark - Out-of-Bounds Read
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-125 Aug 07, 2016