CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2016-3818 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Android <4.4.4 - DoS
libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28740702.
CWE-284 Jul 11, 2016
CVE-2016-3816 5.5 MEDIUM EPSS 0.00
Android <2016-07-05 - Info Disclosure
The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.
CWE-200 Jul 11, 2016
CVE-2016-3815 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
NVIDIA Camera Driver - Info Disclosure
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28522274.
CWE-200 Jul 11, 2016
CVE-2016-3814 5.5 MEDIUM EPSS 0.00
NVIDIA camera driver <2016-07-05 - Info Disclosure
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28193342.
CWE-200 Jul 11, 2016
CVE-2016-3813 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Qualcomm USB driver - Info Disclosure
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal bug CR1010222.
CWE-200 Jul 11, 2016
CVE-2016-3812 5.5 MEDIUM EPSS 0.00
Android <2016-07-05 - Info Disclosure
The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28174833 and MediaTek internal bug ALPS02688832.
CWE-200 Jul 11, 2016
CVE-2016-3810 5.5 MEDIUM EPSS 0.00
Mediatek Wi-Fi Driver - Info Disclosure
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02694389.
CWE-200 Jul 11, 2016
CVE-2016-3809 5.5 MEDIUM EPSS 0.00
Android <2016-07-05 - Info Disclosure
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
CWE-200 Jul 11, 2016
CVE-2016-3764 4.0 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-07-01 - Info Disclosure
media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive pointer information via a crafted application, aka internal bug 28377502.
CWE-20 Jul 11, 2016
CVE-2016-3761 4.0 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-07-01 - Info Disclosure
NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.
CWE-200 Jul 11, 2016
CVE-2015-8893 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Memory Corruption
app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to cause a denial of service (OS outage or buffer over-read) via a crafted application, aka Android internal bug 28822690 and Qualcomm internal bug CR822275.
CWE-119 Jul 11, 2016
CVE-2014-9798 5.5 MEDIUM EPSS 0.00
Qualcomm Bootloader - DoS
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via a crafted application, aka Android internal bug 28821448 and Qualcomm internal bug CR681965.
CWE-284 Jul 11, 2016
CVE-2016-2888 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
CWE-79 Jul 08, 2016
CVE-2016-0350 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service <5.0.2-6.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
CWE-79 Jul 08, 2016
CVE-2016-0314 6.5 MEDIUM EPSS 0.00
IBM Jazz Reporting Service <6.0.1 - CSRF
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
Jul 08, 2016
CVE-2016-0313 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service <5.0.2-6.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.
CWE-79 Jul 08, 2016
CVE-2016-0252 5.1 MEDIUM EPSS 0.00
IBM Control Center <6.0.0.1-5.4.2.1 - Info Disclosure
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
CWE-200 Jul 08, 2016
CVE-2016-1444 6.5 MEDIUM EPSS 0.00
Cisco TelePresence VCS/X8.1-8.7 & Expressway X8.1-8.6 - Auth Bypass
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
CWE-20 Jul 07, 2016
CVE-2016-0389 5.3 MEDIUM EPSS 0.00
IBM WAS <8.5.5.9 - Info Disclosure
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-200 Jul 07, 2016
CVE-2016-0230 6.8 MEDIUM EPSS 0.00
IBM Power HMC <8.5.0 - Privilege Escalation
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.
CWE-264 Jul 07, 2016