CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
110,849 results Clear all
CVE-2016-2153 6.1 MEDIUM EPSS 0.00
Moodle < 2.6.11 - XSS
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field in a URL, as demonstrated by a search form field.
CWE-79 May 22, 2016
CVE-2016-2152 6.1 MEDIUM EPSS 0.00
Moodle < 2.6.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.
CWE-79 May 22, 2016
CVE-2016-2151 4.3 MEDIUM EPSS 0.00
Moodle < 2.6.11 - Information Disclosure
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.
CWE-200 May 22, 2016
CVE-2016-4567 6.1 MEDIUM EPSS 0.04
Mediaelementjs Mediaelement.js < 2.20.1 - XSS
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
CWE-79 May 22, 2016
CVE-2016-4566 6.1 MEDIUM EPSS 0.05
Wordpress < 4.5.1 - XSS
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
CWE-79 May 22, 2016
CVE-2016-1564 6.1 MEDIUM EPSS 0.01
WordPress <4.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
CWE-79 May 22, 2016
CVE-2015-8878 5.9 MEDIUM EPSS 0.00
Php < 5.5.28 - Race Condition
main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses.
CWE-119 May 22, 2016
CVE-2015-8834 6.1 MEDIUM EPSS 0.01
Wordpress < 4.2.1 - XSS
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440.
CWE-79 May 22, 2016
CVE-2015-7989 5.4 MEDIUM EPSS 0.00
WordPress <4.3.1 - XSS
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
CWE-79 May 22, 2016
CVE-2015-5715 4.3 MEDIUM 1 Writeup EPSS 0.29
WordPress <4.3.1 - Auth Bypass
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
CWE-264 May 22, 2016
CVE-2015-5714 6.1 MEDIUM 1 Writeup EPSS 0.31
WordPress <4.3.1 - XSS
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
CWE-79 May 22, 2016
CVE-2014-9767 4.3 MEDIUM EPSS 0.00
PHP <5.4.45, 5.5.x <5.5.29, 5.6.x <5.6.13 - Path Traversal
Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive.
CWE-22 May 22, 2016
CVE-2016-1401 6.1 MEDIUM EPSS 0.00
Cisco UCS Central Software <1.4(1a) - XSS
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
CWE-79 May 21, 2016
CVE-2016-4441 6.0 MEDIUM EPSS 0.00
QEMU 53C9X FSC - DoS
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI command.
CWE-119 May 20, 2016
CVE-2016-4439 6.7 MEDIUM EPSS 0.00
QEMU 53C9X FSC - DoS/Arbitrary Code Execution
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
CWE-119 May 20, 2016
CVE-2016-3739 5.3 MEDIUM EPSS 0.01
cURL <7.49.0 - Man-in-the-Middle
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.
CWE-20 May 20, 2016
CVE-2016-2100 5.4 MEDIUM EPSS 0.00
Foreman < 1.10.2 - Improper Access Control
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
CWE-284 May 20, 2016
CVE-2016-1858 6.5 MEDIUM EPSS 0.01
WebKit - Info Disclosure
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
CWE-200 May 20, 2016
CVE-2016-1851 4.6 MEDIUM EPSS 0.00
Apple OS X <10.11.5 - Info Disclosure
The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows physically proximate attackers to reset expired passwords in the lock-screen state via unspecified vectors.
May 20, 2016
CVE-2016-1844 5.3 MEDIUM EPSS 0.01
Apple OS X <10.11.5 - Info Disclosure
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
CWE-284 May 20, 2016