CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2015-5664 6.1 MEDIUM EPSS 0.00
QNAP QTS <4.2.0 - XSS
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 03, 2016
CVE-2016-5733 6.1 MEDIUM EPSS 0.01
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.
CWE-79 Jul 03, 2016
CVE-2016-5732 6.1 MEDIUM EPSS 0.00
phpMyAdmin <4.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.
CWE-79 Jul 03, 2016
CVE-2016-5731 6.1 MEDIUM EPSS 0.00
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - XSS
Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.
CWE-79 Jul 03, 2016
CVE-2016-5730 5.3 MEDIUM EPSS 0.01
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - Info Disclosure
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type, which reveals the full path in an error message.
CWE-200 Jul 03, 2016
CVE-2016-5705 6.1 MEDIUM EPSS 0.01
phpMyAdmin 4.4.x-4.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the user privileges page, (2) an "invalid JSON" error message in the error console, (3) a database name in the central columns implementation, (4) a group name, or (5) a search name in the bookmarks implementation.
CWE-79 Jul 03, 2016
CVE-2016-5704 6.1 MEDIUM EPSS 0.00
phpMyAdmin <4.6.3 - XSS
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
CWE-79 Jul 03, 2016
CVE-2016-5701 6.1 MEDIUM EPSS 0.00
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - Code Injection
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
CWE-74 Jul 03, 2016
CVE-2016-2081 6.1 MEDIUM EPSS 0.00
Vmware Vrealize Log Insight - XSS
Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 03, 2016
CVE-2016-2079 5.9 MEDIUM EPSS 0.00
Vmware Nsx Edge - Information Disclosure
VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors.
CWE-200 Jul 03, 2016
CVE-2015-6931 6.1 MEDIUM EPSS 0.00
Vmware Vcenter Server - XSS
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jul 03, 2016
CVE-2016-2968 6.5 MEDIUM EPSS 0.00
IBM Security Qradar Incident Forensics - Access Control
IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unspecified vectors.
CWE-264 Jul 02, 2016
CVE-2016-2961 5.3 MEDIUM EPSS 0.00
IBM Integration Bus - Information Disclosure
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.
CWE-200 Jul 02, 2016
CVE-2016-2883 5.4 MEDIUM EPSS 0.00
IBM Tririga Application Platform - XSS
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0387.
CWE-79 Jul 02, 2016
CVE-2016-2882 4.3 MEDIUM EPSS 0.00
IBM Tririga Application Platform - Information Disclosure
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.
CWE-200 Jul 02, 2016
CVE-2016-2872 5.3 MEDIUM EPSS 0.00
IBM Qradar Security Information And Event Manager - Path Traversal
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
CWE-22 Jul 02, 2016
CVE-2016-1440 5.3 MEDIUM EPSS 0.00
Cisco WSA <9.1.0-070 - DoS
The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the control connection after a file transfer, aka Bug ID CSCuy43468.
CWE-399 Jul 02, 2016
CVE-2016-0400 6.1 MEDIUM 1 PoC Analysis EPSS 0.03
IBM WebSphere eXtreme Scale <7.1.0.3-8.6.0.8 - CRLF Injection
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Jul 02, 2016
CVE-2016-0399 5.4 MEDIUM EPSS 0.00
IBM Maximo Asset Management <7.1.1.13, <7.5.0.9 - XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jul 02, 2016
CVE-2016-0398 4.3 MEDIUM EPSS 0.00
IBM Cognos Analytics <11.0.2 - XSS
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.
CWE-20 Jul 02, 2016