CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
110,849 results Clear all
CVE-2016-1839 5.5 MEDIUM 1 PoC Analysis EPSS 0.11
libxml2 <2.9.4 - DoS
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CWE-125 May 20, 2016
CVE-2016-1838 5.5 MEDIUM 1 PoC Analysis EPSS 0.11
libxml2 <2.9.4 - DoS
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CWE-125 May 20, 2016
CVE-2016-1837 5.5 MEDIUM EPSS 0.01
libxml2 <2.9.4 - Use After Free
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
CWE-416 May 20, 2016
CVE-2016-1836 5.5 MEDIUM EPSS 0.01
libxml2 <2.9.4 - Use After Free
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
CWE-416 May 20, 2016
CVE-2016-1833 5.5 MEDIUM EPSS 0.01
libxml2 <2.9.4 - DoS
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CWE-125 May 20, 2016
CVE-2016-1814 5.5 MEDIUM EPSS 0.00
Apple iOS <9.3.2-OS X <10.11.5-tvOS <9.2.1 - DoS
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
CWE-476 May 20, 2016
CVE-2016-1811 6.5 MEDIUM EPSS 0.01
Apple iOS <9.3.2, OS X <10.11.5, tvOS <9.2.1, watchOS <2.2.1 - DoS
ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
CWE-476 May 20, 2016
CVE-2016-1807 5.1 MEDIUM 1 PoC Analysis EPSS 0.00
Apple <9.3.2, <10.11.5, <9.2.1, <2.2.1 - Info Disclosure
Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecified vectors.
CWE-362 May 20, 2016
CVE-2016-1802 5.5 MEDIUM EPSS 0.00
Apple iOS <9.3.2, OS X <10.11.5, tvOS <9.2.1, watchOS <2.2.1 - Info...
CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.
CWE-200 May 20, 2016
CVE-2016-0731 4.9 MEDIUM EPSS 0.00
Apache Ambari <2.2.1 - Info Disclosure
The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
CWE-284 May 18, 2016
CVE-2016-4425 6.5 MEDIUM EPSS 0.01
Jansson <2.7 - DoS
Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.
CWE-674 May 17, 2016
CVE-2016-3727 4.3 MEDIUM EPSS 0.00
Jenkins <2.3, <1.651.2 - Info Disclosure
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
CWE-200 May 17, 2016
CVE-2016-3725 4.3 MEDIUM EPSS 0.00
Jenkins <2.3 & LTS <1.651.2 - Privilege Escalation
Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption).
CWE-264 May 17, 2016
CVE-2016-3724 6.5 MEDIUM EPSS 0.00
Jenkins <2.3 & LTS <1.651.2 - Info Disclosure
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
CWE-200 May 17, 2016
CVE-2016-3723 4.3 MEDIUM EPSS 0.00
Jenkins <2.3 & LTS <1.651.2 - Info Disclosure
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
CWE-200 May 17, 2016
CVE-2016-3722 4.3 MEDIUM EPSS 0.00
Jenkins <2.3, LTS <1.651.2 - DoS
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."
CWE-264 May 17, 2016
CVE-2016-3721 4.3 MEDIUM EPSS 0.00
Jenkins <2.3, <1.651.2 - Command Injection
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
CWE-17 May 17, 2016
CVE-2016-0323 6.5 MEDIUM EPSS 0.00
Liberty for Java <2.7-20160321-1358 - Privilege Escalation
The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.
CWE-284 May 17, 2016
CVE-2016-0306 5.9 MEDIUM EPSS 0.00
IBM WebSphere Application Server (WAS) <7.0.0.41, <8.0.0.13, <8.5.5...
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CWE-200 May 17, 2016
CVE-2015-8838 5.9 MEDIUM EPSS 0.01
Php < 5.4.42 - Improper Access Control
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
CWE-284 May 16, 2016