CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
110,849 results Clear all
CVE-2016-3226 6.5 MEDIUM EPSS 0.13
Microsoft Windows Server 2008 - Improper Access Control
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."
CWE-284 Jun 16, 2016
CVE-2016-3216 4.3 MEDIUM 1 PoC Analysis EPSS 0.38
Microsoft Windows 10 - Information Disclosure
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows Graphics Component Information Disclosure Vulnerability."
CWE-200 Jun 16, 2016
CVE-2016-3215 5.5 MEDIUM EPSS 0.38
Microsoft Windows 10 - Information Disclosure
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
CWE-200 Jun 16, 2016
CVE-2016-3212 6.1 MEDIUM EXPLOITED EPSS 0.22
Microsoft Internet Explorer - XSS
The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, aka "Internet Explorer XSS Filter Vulnerability."
CWE-79 Jun 16, 2016
CVE-2016-3201 6.5 MEDIUM EPSS 0.31
Microsoft Edge - Information Disclosure
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.
CWE-200 Jun 16, 2016
CVE-2016-3198 6.5 MEDIUM EPSS 0.35
Microsoft Edge - Security Feature Bypass
Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
CWE-254 Jun 16, 2016
CVE-2016-0028 5.5 MEDIUM EPSS 0.21
Microsoft Outlook Web Access - Information Disclosure
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."
CWE-200 Jun 16, 2016
CVE-2016-5337 5.5 MEDIUM EPSS 0.00
QEMU - Info Disclosure
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
Jun 14, 2016
CVE-2016-5238 4.4 MEDIUM EPSS 0.00
Qemu < 2.6.2 - Out-of-Bounds Write
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
CWE-787 Jun 14, 2016
CVE-2016-5104 5.3 MEDIUM EPSS 0.02
Libimobiledevice < 1.2.0 - Improper Access Control
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
CWE-284 Jun 13, 2016
CVE-2016-4911 4.3 MEDIUM EPSS 0.00
Keystone Openstack Identity < 9.0.1 - Improper Access Control
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
CWE-284 Jun 13, 2016
CVE-2016-4005 5.5 MEDIUM EPSS 0.00
Huawei Hilink App <3.19.2 - Info Disclosure
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
CWE-310 Jun 13, 2016
CVE-2016-3677 6.5 MEDIUM EPSS 0.00
Huawei Wear App <15.0.0.307 - Info Disclosure
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
CWE-345 Jun 13, 2016
CVE-2016-3670 6.1 MEDIUM 1 PoC Analysis EPSS 0.09
Liferay <7.0.0 - XSS
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstName field.
CWE-79 Jun 13, 2016
CVE-2016-2833 6.1 MEDIUM EPSS 0.00
Opensuse Leap < 46.0.1 - Security Feature Bypass
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
CWE-254 Jun 13, 2016
CVE-2016-2832 4.3 MEDIUM EPSS 0.00
Canonical Ubuntu Linux < 46.0.1 - Information Disclosure
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
CWE-200 Jun 13, 2016
CVE-2016-2829 6.5 MEDIUM EPSS 0.00
Opensuse Leap < 46.0.1 - Improper Access Control
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
CWE-284 Jun 13, 2016
CVE-2016-2825 6.5 MEDIUM EPSS 0.01
Canonical Ubuntu Linux < 46.0.1 - Improper Access Control
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
CWE-284 Jun 13, 2016
CVE-2016-2822 6.5 MEDIUM EPSS 0.01
Debian Linux < 46.0.1 - Improper Access Control
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
CWE-284 Jun 13, 2016
CVE-2016-2500 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.
CWE-200 Jun 13, 2016