CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2016-1439 6.1 MEDIUM EPSS 0.00
Cisco Unified Contact Center Enterprise <10.5(2) - XSS
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.
CWE-79 Jun 23, 2016
CVE-2016-1437 6.5 MEDIUM EPSS 0.00
Cisco Prime Collaboration Deployment <11.5.1 - SQL Injection
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.
CWE-89 Jun 23, 2016
CVE-2016-1434 6.5 MEDIUM EPSS 0.00
Cisco 8800 <11.0(1) - File Deletion
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
CWE-22 Jun 23, 2016
CVE-2016-1428 6.5 MEDIUM EPSS 0.00
Cisco IOS XE <3.17S - Use After Free
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.
CWE-399 Jun 23, 2016
CVE-2016-0914 6.3 MEDIUM EPSS 0.00
EMC Documentum <7.2-6.8 - Auth Bypass
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
CWE-284 Jun 23, 2016
CVE-2016-2178 5.5 MEDIUM EPSS 0.00
Openssl < 0.10.47 - Information Disclosure
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
CWE-203 Jun 20, 2016
CVE-2015-8288 5.9 MEDIUM EPSS 0.01
NETGEAR - Cryptographic Protection Bypass
NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Jun 20, 2016
CVE-2016-4811 5.6 MEDIUM EPSS 0.00
Ntt-bp Japan Connected-free Wi-fi - Improper Access Control
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
CWE-284 Jun 19, 2016
CVE-2016-4530 6.5 MEDIUM EPSS 0.01
Osisoft PI Sql Data Access Server 2016 - Improper Input Validation
OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message.
CWE-20 Jun 19, 2016
CVE-2016-4518 6.5 MEDIUM EPSS 0.00
Osisoft PI AF Server 2016 < 2.7.0 - Improper Input Validation
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.
CWE-20 Jun 19, 2016
CVE-2016-1864 4.3 MEDIUM EPSS 0.01
WebKit - XSS
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
CWE-200 Jun 19, 2016
CVE-2016-1196 4.3 MEDIUM EPSS 0.00
Cybozu Garoon <4.2.1 - Auth Bypass
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.
CWE-200 Jun 19, 2016
CVE-2016-1192 4.3 MEDIUM EPSS 0.00
Cybozu Garoon <4.2 - Path Traversal
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.
CWE-22 Jun 19, 2016
CVE-2016-1191 5.3 MEDIUM EPSS 0.01
Cybozu Garoon <4.2.1 - Path Traversal
Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.
CWE-22 Jun 19, 2016
CVE-2015-7776 4.3 MEDIUM EPSS 0.01
Cybozu Garoon <4.2.0 - XSS
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.
CWE-200 Jun 19, 2016
CVE-2015-7462 4.4 MEDIUM EPSS 0.00
IBM WebSphere MQ 8.0.0.4 - Info Disclosure
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.
CWE-200 Jun 19, 2016
CVE-2016-1226 6.1 MEDIUM EPSS 0.00
Trend Micro Internet Security <8,10 - XSS
Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 19, 2016
CVE-2016-1225 6.5 MEDIUM EPSS 0.01
Trend Micro Internet Security <8,10 - Info Disclosure
Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.
CWE-200 Jun 19, 2016
CVE-2016-1197 6.1 MEDIUM EPSS 0.00
Cybozu Garoon <4.2.1 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7775.
CWE-79 Jun 19, 2016
CVE-2015-7775 5.4 MEDIUM EPSS 0.00
Cybozu Garoon 4.0.3 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.
CWE-79 Jun 19, 2016