CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2016-0387 5.4 MEDIUM EPSS 0.00
IBM TRIRIGA Application Platform <3.3.2.6, <3.4.2.4, <3.5.0.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.
CWE-79 Jul 02, 2016
CVE-2016-0365 5.9 MEDIUM EPSS 0.00
IBM UrbanCode Deploy <6.0.1.13, <6.1.3.3, <6.2.1.1 - Auth Bypass
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.
CWE-200 Jul 01, 2016
CVE-2016-0364 4.3 MEDIUM EPSS 0.00
IBM UrbanCode Deploy <6.0.1.13-6.2.1.1 - Info Disclosure
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
CWE-200 Jul 01, 2016
CVE-2016-5307 4.3 MEDIUM EPSS 0.00
Symantec Endpoint Protection Manager < 12.1.6 - Path Traversal
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.
CWE-22 Jun 30, 2016
CVE-2016-5306 5.3 MEDIUM EPSS 0.00
Symantec Endpoint Protection Manager < 12.1.6 - Information Disclosure
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.
CWE-254 Jun 30, 2016
CVE-2016-5305 5.4 MEDIUM EPSS 0.00
Symantec Endpoint Protection Manager < 12.1.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via a "DOM link manipulation" attack.
CWE-79 Jun 30, 2016
CVE-2016-5304 6.8 MEDIUM 1 PoC Analysis EPSS 0.07
Symantec Endpoint Protection Manager < 12.1.6 - Open Redirect
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Jun 30, 2016
CVE-2016-3652 5.4 MEDIUM 1 PoC Analysis EPSS 0.01
Symantec Endpoint Protection Manager <12.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 30, 2016
CVE-2016-3649 4.3 MEDIUM EPSS 0.00
Symantec Endpoint Protection Manager <12.1 - Info Disclosure
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.
CWE-200 Jun 30, 2016
CVE-2016-3189 6.5 MEDIUM EPSS 0.24
Bzip2 < 3.7.13 - Use After Free
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
CWE-416 Jun 30, 2016
CVE-2016-5248 5.5 MEDIUM EPSS 0.00
Lenovo Solution Center < 3.3.002 - Access Control
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.
CWE-264 Jun 30, 2016
CVE-2016-5232 5.5 MEDIUM EPSS 0.00
Huawei Mate 8 Firmware - Memory Corruption
Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (system crash) via a crafted app.
CWE-119 Jun 30, 2016
CVE-2016-4086 5.3 MEDIUM EPSS 0.00
Huawei HiSuite <4.0.4.301-4.0.4.204 - RCE
Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.
Jun 30, 2016
CVE-2016-4057 6.5 MEDIUM EPSS 0.00
Huawei FusionCompute <V100R005C10SPC700 - DoS
Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.
CWE-399 Jun 30, 2016
CVE-2016-0349 6.5 MEDIUM EPSS 0.00
IBM Business Process Manager <8.5.7 - Auth Bypass
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
CWE-284 Jun 30, 2016
CVE-2016-0322 5.4 MEDIUM EPSS 0.00
IBM Connections <5.5 - XSS
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.
CWE-79 Jun 30, 2016
CVE-2016-5834 6.1 MEDIUM EPSS 0.01
WordPress <4.5.3 - XSS
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
CWE-79 Jun 29, 2016
CVE-2016-5833 6.1 MEDIUM EPSS 0.01
WordPress <4.5.3 - XSS
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
CWE-79 Jun 29, 2016
CVE-2016-1237 5.5 MEDIUM EPSS 0.00
Linux kernel <4.6.3 - Privilege Escalation
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
CWE-284 Jun 29, 2016
CVE-2016-0298 6.5 MEDIUM EPSS 0.00
IBM Security Guardium Database Activity Monitor <10 - Path Traversal
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
CWE-200 Jun 29, 2016