CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
110,849 results Clear all
CVE-2016-4585 6.1 MEDIUM EPSS 0.01
Apple Webkit - XSS
Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari.
CWE-79 Jul 22, 2016
CVE-2016-1865 5.5 MEDIUM EPSS 0.00
Apple iOS <9.3.3, OS X <10.11.6, tvOS <9.2.2, watchOS <2.2.2 - DoS
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
CWE-476 Jul 22, 2016
CVE-2016-5477 5.8 MEDIUM EPSS 0.00
Oracle GlassFish Server - Info Disclosure
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1 and 3.0.1 allows remote attackers to affect confidentiality via vectors related to Administration.
Jul 21, 2016
CVE-2016-5471 5.5 MEDIUM EPSS 0.00
Oracle Sun Solaris 11.3 - DoS
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-3497 and CVE-2016-5469.
Jul 21, 2016
CVE-2016-5470 6.5 MEDIUM EPSS 0.01
Oracle PeopleSoft Products <8.55 - Info Disclosure
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality via vectors related to Application Designer.
Jul 21, 2016
CVE-2016-5469 5.5 MEDIUM EPSS 0.00
Oracle Sun Solaris 11.3 - DoS
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-3497 and CVE-2016-5471.
Jul 21, 2016
CVE-2016-5468 5.4 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.2.2 - Info Disclosure
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality and integrity via vectors related to EAI, a different vulnerability than CVE-2016-5451.
Jul 21, 2016
CVE-2016-5467 5.4 MEDIUM EPSS 0.00
Oracle PeopleSoft <9.2 - Info Disclosure
Unspecified vulnerability in the PeopleSoft Enterprise FSCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to eProcurement.
Jul 21, 2016
CVE-2016-5464 4.1 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.2.2 - Info Disclosure
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5463.
Jul 21, 2016
CVE-2016-5463 4.1 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.2.2 - Info Disclosure
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5464.
Jul 21, 2016
CVE-2016-5461 6.5 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.3 - Info Disclosure
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Object Manager.
Jul 21, 2016
CVE-2016-5459 4.7 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.3 - Info Disclosure
Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect integrity via vectors related to iHelp.
Jul 21, 2016
CVE-2016-5458 6.4 MEDIUM EPSS 0.00
Oracle Communications EAGLE <16.0 - Info Disclosure
Unspecified vulnerability in the Oracle Communications EAGLE Application Processor component in Oracle Communications Applications 16.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to APPL.
Jul 21, 2016
CVE-2016-5456 5.3 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.3 - Info Disclosure
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Services.
Jul 21, 2016
CVE-2016-5455 5.3 MEDIUM EPSS 0.00
Oracle Communications <8.0 - Info Disclosure
Unspecified vulnerability in the Oracle Communications Messaging Server component in Oracle Communications Applications 6.3, 7.0, and 8.0 allows remote attackers to affect confidentiality via vectors related to Multiplexor.
Jul 21, 2016
CVE-2016-5454 6.4 MEDIUM EPSS 0.00
Oracle Sun Solaris 11.3 - Privilege Escalation
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Verified Boot.
Jul 21, 2016
CVE-2016-5452 5.5 MEDIUM EPSS 0.00
Oracle Sun Solaris 11.3 - Info Disclosure
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality via vectors related to Verified Boot.
Jul 21, 2016
CVE-2016-5450 4.7 MEDIUM EPSS 0.00
Oracle Siebel CRM <8.2.2 - Info Disclosure
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect integrity via vectors related to UIF Open UI.
Jul 21, 2016
CVE-2016-5448 6.5 MEDIUM EPSS 0.01
Oracle Sun Systems Products Suite <3.2 - RCE
Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect integrity and availability via vectors related to SNMP.
Jul 21, 2016
CVE-2016-5443 4.7 MEDIUM EPSS 0.00
Oracle MySQL <5.7.12 - DoS
Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows local users to affect availability via vectors related to Server: Connection.
Jul 21, 2016