CVE & Exploit Intelligence Database

Updated 29m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
110,849 results Clear all
CVE-2016-4178 4.3 MEDIUM EPSS 0.01
Adobe Flash Player <18.0.0.366,19.x-22.x - Auth Bypass
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
CWE-863 Jul 13, 2016
CVE-2016-3287 4.4 MEDIUM EPSS 0.00
Microsoft Windows 10 - Security Feature Bypass
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."
CWE-254 Jul 13, 2016
CVE-2016-3279 5.5 MEDIUM EPSS 0.34
Microsoft Excel - Security Feature Bypass
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
CWE-254 Jul 13, 2016
CVE-2016-3277 5.3 MEDIUM EPSS 0.33
Microsoft Edge - Information Disclosure
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
CWE-200 Jul 13, 2016
CVE-2016-3273 5.3 MEDIUM EPSS 0.23
Microsoft Edge - Information Disclosure
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
CWE-200 Jul 13, 2016
CVE-2016-3271 6.5 MEDIUM EPSS 0.26
Microsoft Edge - Information Disclosure
The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."
CWE-200 Jul 13, 2016
CVE-2016-3261 5.3 MEDIUM EPSS 0.37
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
CWE-200 Jul 13, 2016
CVE-2016-3258 4.7 MEDIUM EPSS 0.00
Microsoft Windows 10 - Race Condition
Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
CWE-362 Jul 13, 2016
CVE-2016-3256 5.0 MEDIUM EPSS 0.05
Microsoft Windows 10 - Information Disclosure
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."
CWE-200 Jul 13, 2016
CVE-2016-3245 6.5 MEDIUM EPSS 0.11
Microsoft Internet Explorer - Improper Access Control
Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."
CWE-284 Jul 13, 2016
CVE-2016-3244 4.3 MEDIUM EPSS 0.22
Microsoft Edge - Improper Access Control
Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge Security Feature Bypass."
CWE-284 Jul 13, 2016
CVE-2016-5850 5.4 MEDIUM EPSS 0.00
Huawei Public Cloud Solution <1.0.5 - XSS
Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 12, 2016
CVE-2016-5009 6.5 MEDIUM EPSS 0.01
Redhat Ceph Storage Mon < 0.94.6 - Improper Input Validation
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CWE-20 Jul 12, 2016
CVE-2016-4428 5.4 MEDIUM EPSS 0.01
OpenStack Horizon <9.0.1 - XSS
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
CWE-79 Jul 12, 2016
CVE-2016-2219 5.4 MEDIUM EPSS 0.00
Paloaltonetworks Pan-os - XSS
Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 12, 2016
CVE-2015-3192 5.5 MEDIUM EPSS 0.01
Pivotal Spring Framework <3.2.14 & 4.x <4.1.7 - DoS
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
CWE-119 Jul 12, 2016
CVE-2016-5308 5.5 MEDIUM EPSS 0.03
Symantec Client Intrusion Detection System - Memory Corruption
The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memory corruption and system crash) via a malformed Portable Executable (PE) file.
CWE-119 Jul 12, 2016
CVE-2016-2206 5.7 MEDIUM EPSS 0.00
Symantec Workspace Streaming - Access Control
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
CWE-264 Jul 12, 2016
CVE-2016-2205 5.7 MEDIUM EPSS 0.00
Symantec Workspace Streaming - Path Traversal
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
CWE-22 Jul 12, 2016
CVE-2016-1445 5.3 MEDIUM EPSS 0.00
Cisco ASA <9.4.3.3 - Auth Bypass
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
Jul 12, 2016