CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2016-6170 6.5 MEDIUM 1 Writeup EPSS 0.13
ISC BIND <9.11.0b1 - DoS
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.
CWE-20 Jul 06, 2016
CVE-2016-4508 6.1 MEDIUM EPSS 0.01
Bosch Bladecontrol-webvis < 3.0.2 - XSS
Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 06, 2016
CVE-2016-4507 6.4 MEDIUM EPSS 0.00
Bosch Bladecontrol-webvis < 3.0.2 - SQL Injection
SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Jul 06, 2016
CVE-2016-1546 5.9 MEDIUM EPSS 0.42
Apache HTTP Server <2.4.17-2.4.18 - DoS
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
CWE-399 Jul 06, 2016
CVE-2016-5099 6.1 MEDIUM EPSS 0.00
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
CWE-79 Jul 05, 2016
CVE-2016-5098 5.3 MEDIUM EPSS 0.00
Phpmyadmin - Path Traversal
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
CWE-22 Jul 05, 2016
CVE-2016-5097 5.3 MEDIUM EPSS 0.01
Opensuse < 4.6.1 - Information Disclosure
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
CWE-200 Jul 05, 2016
CVE-2016-4956 5.3 MEDIUM EPSS 0.01
Ntp < 4.2.8 - Denial of Service
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
Jul 05, 2016
CVE-2016-4955 5.9 MEDIUM EPSS 0.02
Ntp < 4.2.8 - Race Condition
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
CWE-362 Jul 05, 2016
CVE-2016-4465 5.3 MEDIUM EPSS 0.10
Apache Struts < 2.3.29 - Improper Input Validation
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
CWE-20 Jul 04, 2016
CVE-2016-5848 6.7 MEDIUM EPSS 0.00
Siemens SICAM PAS <8.07 - Info Disclosure
Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
CWE-200 Jul 04, 2016
CVE-2016-0899 6.3 MEDIUM EPSS 0.00
EMC RSA Archer GRC <5.5.3.4 - Info Disclosure
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.
CWE-200 Jul 04, 2016
CVE-2016-6130 4.7 MEDIUM EPSS 0.00
Linux kernel <4.6 - Info Disclosure
Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerability.
CWE-362 Jul 03, 2016
CVE-2016-2862 6.1 MEDIUM EPSS 0.00
IBM Websphere Commerce - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jul 03, 2016
CVE-2016-1425 6.5 MEDIUM EPSS 0.01
Cisco IOS - DoS
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
CWE-119 Jul 03, 2016
CVE-2016-1398 6.5 MEDIUM EPSS 0.00
Cisco - Buffer Overflow
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote authenticated users to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCux86669.
CWE-119 Jul 03, 2016
CVE-2016-0359 6.1 MEDIUM EPSS 0.00
IBM WebSphere Application Server <7.0.0.43, <8.0.0.13, <8.5 Full <8...
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Jul 03, 2016
CVE-2016-0346 5.4 MEDIUM EPSS 0.00
IBM Cognos Business Intelligence <10.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jul 03, 2016
CVE-2016-0221 5.4 MEDIUM EPSS 0.00
IBM Cognos TM1 <10.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jul 03, 2016
CVE-2016-4509 6.0 MEDIUM EPSS 0.03
Eaton Elcsoft < 2.4.01 - Memory Corruption
Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file.
CWE-119 Jul 03, 2016