CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
110,849 results Clear all
CVE-2014-8177 6.5 MEDIUM EPSS 0.00
Redhat Gluster Storage Management Console - Improper Access Control
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.
CWE-284 Jun 07, 2016
CVE-2016-1702 6.5 MEDIUM EPSS 0.01
Skia <51.0.2704.79 - DoS
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.
CWE-119 Jun 05, 2016
CVE-2016-1699 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
WebKit/Source/devtools/front_end/devtools.js - Info Disclosure
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
CWE-284 Jun 05, 2016
CVE-2016-1698 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
Google Chrome <51.0.2704.79 - Code Injection
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
CWE-200 Jun 05, 2016
CVE-2016-1694 5.3 MEDIUM EPSS 0.01
Google Chrome <51.0.2704.63 - Info Disclosure
browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.
CWE-284 Jun 05, 2016
CVE-2016-1693 5.3 MEDIUM EPSS 0.01
Google Chrome <51.0.2704.63 - Man-in-the-Middle
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
CWE-284 Jun 05, 2016
CVE-2016-1692 5.3 MEDIUM EPSS 0.01
Google Chrome <51.0.2704.63 - SSRF
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
CWE-284 Jun 05, 2016
CVE-2016-1689 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
Google Chrome <51.0.2704.63 - Buffer Overflow
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
CWE-119 Jun 05, 2016
CVE-2016-1688 6.5 MEDIUM 1 PoC Analysis EPSS 0.05
Google V8 <5.0.71.40 - DoS
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
CWE-119 Jun 05, 2016
CVE-2016-1687 6.5 MEDIUM 1 PoC Analysis EPSS 0.02
Google Chrome <51.0.2704.63 - Info Disclosure
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
CWE-200 Jun 05, 2016
CVE-2016-1686 6.5 MEDIUM EPSS 0.01
PDFium - DoS
The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
CWE-119 Jun 05, 2016
CVE-2016-1685 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
Google Chrome <51.0.2704.63 - DoS
core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
CWE-119 Jun 05, 2016
CVE-2016-1682 6.1 MEDIUM 1 PoC Analysis EPSS 0.01
WebKit/Blink <51.0.2704.63 - Auth Bypass
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.
CWE-284 Jun 05, 2016
CVE-2016-1677 6.5 MEDIUM 1 PoC Analysis EPSS 0.13
Google V8 <5.1.281.26 - Info Disclosure
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
CWE-200 Jun 05, 2016
CVE-2016-1230 6.1 MEDIUM EPSS 0.00
NTT PC Communications WebARENA Service <2.2.1 - XSS
Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 05, 2016
CVE-2016-1229 5.4 MEDIUM EPSS 0.00
HumHub <1.0.0-beta.3 - XSS
Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 05, 2016
CVE-2016-1222 6.1 MEDIUM EPSS 0.00
Kobe Beauty php-contact-form <2016-05-18 - XSS
Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
CWE-79 Jun 05, 2016
CVE-2016-4812 6.1 MEDIUM EPSS 0.00
Markdown ON Saved Improved < 2.5 - XSS
Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2016
CVE-2016-1211 6.1 MEDIUM EPSS 0.00
Epoch Web Mailing List <0.31 - XSS
Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List 0.31 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2016
CVE-2016-0908 6.7 MEDIUM EPSS 0.00
EMC Isilon OneFS <7.1.1.9, <7.2.1.2 - Privilege Escalation
EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leveraging administrative privileges.
CWE-264 Jun 04, 2016