CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2015-8699 6.1 MEDIUM EPSS 0.00
Broadcom Release Automation < 5.0.2-227 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 29, 2016
CVE-2016-0229 6.1 MEDIUM EPSS 0.00
IBM Marketing Platform <9.1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jun 28, 2016
CVE-2016-5728 6.3 MEDIUM EPSS 0.00
Linux kernel <4.6.1 - Info Disclosure
Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.
CWE-119 Jun 27, 2016
CVE-2016-5243 5.5 MEDIUM EPSS 0.00
Linux Kernel < 4.6.3 - Information Disclosure
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
CWE-200 Jun 27, 2016
CVE-2016-4470 5.5 MEDIUM EPSS 0.00
Oracle VM Server < 4.6.3 - Denial of Service
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
Jun 27, 2016
CVE-2014-9903 5.5 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to obtain sensitive information from kernel stack memory via a crafted sched_getattr system call.
CWE-200 Jun 27, 2016
CVE-2016-5087 4.4 MEDIUM EPSS 0.00
Alertus Desktop Notification For OS X < 2.9.30.1700 - Access Control
Alertus Desktop Notification before 2.9.31.1710 on OS X uses weak permissions for configuration files and unspecified other files, which allows local users to suppress emergency notifications or change content via standard filesystem operations.
CWE-264 Jun 26, 2016
CVE-2016-4513 6.1 MEDIUM EPSS 0.00
Schneider-electric Powerlogic Pm8ecc Firmware < 2.60 - XSS
Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 26, 2016
CVE-2016-4828 6.5 MEDIUM EPSS 0.00
Welcart <1.8.3 - Info Disclosure
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account.
CWE-19 Jun 25, 2016
CVE-2016-4827 6.1 MEDIUM EPSS 0.00
Welcart E-commerce < 1.8.3 - XSS
Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4826.
CWE-79 Jun 25, 2016
CVE-2016-4826 6.1 MEDIUM EPSS 0.00
Welcart E-commerce < 1.8.3 - XSS
Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4827.
CWE-79 Jun 25, 2016
CVE-2016-4825 5.6 MEDIUM EPSS 0.10
Welcart E-commerce < 1.8.3 - Improper Input Validation
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.
CWE-20 Jun 25, 2016
CVE-2016-4824 5.3 MEDIUM EPSS 0.00
Corega Cg-wlr300gnv Firmware - Security Feature Bypass
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack.
CWE-254 Jun 25, 2016
CVE-2016-1190 6.5 MEDIUM EPSS 0.00
Cybozu Garoon <4.2 - Auth Bypass
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.
CWE-284 Jun 25, 2016
CVE-2016-1188 6.5 MEDIUM EPSS 0.00
Cybozu Garoon <4.2.1 - Open Redirect
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.
Jun 25, 2016
CVE-2016-4528 5.0 MEDIUM EPSS 0.00
Advantech Webaccess < 8.1 - Memory Corruption
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.
CWE-119 Jun 25, 2016
CVE-2016-4525 6.6 MEDIUM EPSS 0.00
Advantech WebAccess <8.1_20160519 - Info Disclosure
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
Jun 25, 2016
CVE-2016-5709 4.7 MEDIUM EPSS 0.00
SolarWinds Virtualization Manager <6.3.1 - Info Disclosure
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
CWE-200 Jun 24, 2016
CVE-2016-5435 5.9 MEDIUM EPSS 0.00
Huawei Firmware - Resource Management Error
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause a denial of service (memory consumption and reboot) via a crafted packet.
CWE-399 Jun 24, 2016
CVE-2016-5021 4.9 MEDIUM EPSS 0.00
F5 Big-iq Application Delivery Controller - Information Disclosure
The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 allows remote authenticated administrators to obtain sensitive information via unspecified vectors.
CWE-200 Jun 24, 2016