CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
110,849 results Clear all
CVE-2016-3712 5.5 MEDIUM EPSS 0.00
QEMU - DoS
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
CWE-190 May 11, 2016
CVE-2016-1236 6.1 MEDIUM EPSS 0.00
WebSVN - XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.
CWE-79 May 11, 2016
CVE-2016-1115 5.9 MEDIUM EPSS 0.02
Adobe Coldfusion - Improper Input Validation
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
CWE-20 May 11, 2016
CVE-2016-1113 6.1 MEDIUM EPSS 0.01
Adobe Coldfusion - XSS
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 11, 2016
CVE-2016-0194 5.3 MEDIUM EPSS 0.01
Microsoft Internet Explorer <11 - Info Disclosure
Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
CWE-200 May 11, 2016
CVE-2016-0190 5.5 MEDIUM EPSS 0.02
Microsoft Windows <8.1 - Info Disclosure
Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted a disk, which allows local users to read arbitrary files on these disks via RemoteFX requests, aka "Remote Desktop Protocol Drive Redirection Information Disclosure Vulnerability."
CWE-200 May 11, 2016
CVE-2016-0181 5.5 MEDIUM EPSS 0.00
Microsoft Windows 10 - Security Feature Bypass
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass."
CWE-254 May 11, 2016
CVE-2016-0169 6.5 MEDIUM 1 PoC Analysis EPSS 0.63
Microsoft Windows 10 - Information Disclosure
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0168.
CWE-200 May 11, 2016
CVE-2016-0168 6.5 MEDIUM 1 PoC Analysis EPSS 0.70
Microsoft Windows 10 - Information Disclosure
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0169.
CWE-200 May 11, 2016
CVE-2016-0149 5.9 MEDIUM EPSS 0.16
Microsoft .net Framework - Information Disclosure
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."
CWE-200 May 11, 2016
CVE-2016-4561 6.1 MEDIUM EPSS 0.00
Ikiwiki < 3.20160121 - XSS
Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message.
CWE-79 May 10, 2016
CVE-2015-5208 4.4 MEDIUM EPSS 0.02
Apache Cordova iOS <4.0.0 - RCE
Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.
CWE-20 May 09, 2016
CVE-2015-5207 5.3 MEDIUM EPSS 0.00
Apache Cordova iOS <4.0.0 - Auth Bypass
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
CWE-284 May 09, 2016
CVE-2016-2460 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Google Android - Information Disclosure
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27555981.
CWE-200 May 09, 2016
CVE-2016-2459 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27556038.
CWE-200 May 09, 2016
CVE-2016-2458 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a crafted application, related to ComposeActivity.java and ComposeActivityEmail.java, aka internal bug 27335139.
CWE-200 May 09, 2016
CVE-2016-2457 5.5 MEDIUM EPSS 0.00
Google Android - Access Control
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes by leveraging guest access, aka internal bug 27411179.
CWE-264 May 09, 2016
CVE-2016-2454 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Improper Input Validation
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
CWE-20 May 09, 2016
CVE-2016-2350 6.1 MEDIUM EPSS 0.00
Accellion File Transfer Appliance < 9_11_210 - XSS
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) move_partition_frame.html, or (3) wmInfo.html.
CWE-79 May 07, 2016
CVE-2015-6551 5.9 MEDIUM EPSS 0.00
Veritas Netbackup Appliance - Information Disclosure
Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets.
CWE-200 May 07, 2016