CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
110,849 results Clear all
CVE-2016-2013 6.5 MEDIUM EPSS 0.00
HPE Network Node Manager i <10.02 - Info Disclosure
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CWE-200 May 07, 2016
CVE-2016-2012 6.5 MEDIUM EPSS 0.00
HPE Network Node Manager i <10.02 - Auth Bypass
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.
CWE-287 May 07, 2016
CVE-2016-2011 5.4 MEDIUM EPSS 0.00
HPE Network Node Manager i <10.02 - XSS
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
CWE-79 May 07, 2016
CVE-2016-2010 5.4 MEDIUM EPSS 0.00
HPE Network Node Manager i <10.02 - XSS
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.
CWE-79 May 07, 2016
CVE-2016-0902 5.3 MEDIUM EPSS 0.01
EMC RSA Authentication Manager <8.1 SP1 P14 - HTTP Response Splitting
CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
May 07, 2016
CVE-2016-0901 6.1 MEDIUM EPSS 0.00
EMC RSA Auth Mgr <8.1 SP1 P14 - XSS
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0900.
CWE-79 May 07, 2016
CVE-2016-0900 6.1 MEDIUM EPSS 0.00
EMC RSA Auth Mgr <8.1 SP1 P14 - XSS
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.
CWE-79 May 07, 2016
CVE-2016-4008 5.9 MEDIUM EPSS 0.05
GNU Libtasn1 <4.8 - DoS
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
CWE-399 May 05, 2016
CVE-2016-3718 5.5 MEDIUM KEV 1 PoC Analysis EPSS 0.84
ImageMagick <6.9.3-10, <7.0.1-1 - SSRF
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CWE-918 May 05, 2016
CVE-2016-3717 5.5 MEDIUM 1 PoC Analysis EPSS 0.34
ImageMagick <6.9.3-10, <7.0.1-1 - Info Disclosure
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
CWE-200 May 05, 2016
CVE-2016-3715 5.5 MEDIUM KEV 1 PoC Analysis EPSS 0.78
ImageMagick <6.9.3-10, <7.0.1-1 - RCE
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
CWE-552 May 05, 2016
CVE-2016-2168 6.5 MEDIUM EPSS 0.09
Apache Subversion < 1.8.15 - Denial of Service
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
May 05, 2016
CVE-2016-2167 6.8 MEDIUM EPSS 0.01
Apache Subversion < 1.8.15 - Improper Access Control
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
CWE-284 May 05, 2016
CVE-2016-2107 5.9 MEDIUM 3 PoCs Analysis EPSS 0.80
Redhat Enterprise Linux Desktop < 1.0.1s - Information Disclosure
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
CWE-310 May 05, 2016
CVE-2016-0895 4.3 MEDIUM EPSS 0.00
EMC RSA Data Loss Prevention <9.6 - CSRF
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to conduct clickjacking attacks via web-site elements with crafted transparency or opacity.
CWE-20 May 03, 2016
CVE-2016-0894 6.3 MEDIUM EPSS 0.00
EMC RSA Data Loss Prevention <9.6 - Auth Bypass
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified parameter.
CWE-254 May 03, 2016
CVE-2016-0893 4.3 MEDIUM EPSS 0.00
EMC RSA DLP <9.6 - Info Disclosure
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.
CWE-200 May 03, 2016
CVE-2016-0892 6.1 MEDIUM EPSS 0.00
EMC RSA Data Loss Prevention <9.6 - XSS
Cross-site scripting (XSS) vulnerability in EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 03, 2016
CVE-2016-3951 4.6 MEDIUM EPSS 0.00
Linux kernel <4.5 - Use After Free
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
May 02, 2016
CVE-2016-3689 4.6 MEDIUM EPSS 0.00
Linux kernel <4.5.1 - DoS
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
May 02, 2016