CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
110,849 results Clear all
CVE-2016-1916 5.4 MEDIUM EPSS 0.00
BlackBerry Enterprise Server <12.4.1 - XSS
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT screen.
CWE-79 Apr 22, 2016
CVE-2016-1036 6.1 MEDIUM EPSS 0.01
Adobe Analytics Appmeasurement For Flash Library < 4.0 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Analytics AppMeasurement for Flash Library before 4.0.1, when debugTracking is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 22, 2016
CVE-2016-4062 5.5 MEDIUM EPSS 0.00
Foxit Reader & PhantomPDF <7.3.4 - DoS
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
CWE-19 Apr 22, 2016
CVE-2016-1596 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Micro Focus Novell Service Desk <7.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.
CWE-79 Apr 22, 2016
CVE-2016-1595 6.5 MEDIUM 1 PoC Analysis EPSS 0.04
Micro Focus Novell Service Desk <7.2 - SQL Injection
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
CWE-200 Apr 22, 2016
CVE-2016-1594 6.5 MEDIUM 1 PoC Analysis EPSS 0.05
Micro Focus Novell Service Desk <7.2 - Info Disclosure
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
CWE-200 Apr 22, 2016
CVE-2016-3145 4.6 MEDIUM EPSS 0.00
Lexmark Printer Firmware < pp.021.062 - Information Disclosure
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
CWE-200 Apr 22, 2016
CVE-2016-2305 6.1 MEDIUM EPSS 0.00
Ecava Integraxor < 4.2.4502 - XSS
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Apr 22, 2016
CVE-2016-2304 4.3 MEDIUM EPSS 0.00
Ecava Integraxor < 4.2.4502 - Information Disclosure
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CWE-200 Apr 22, 2016
CVE-2016-2303 5.3 MEDIUM EPSS 0.00
Ecava IntegraXor <5.0.4522 - HTTP Response Splitting
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Apr 22, 2016
CVE-2016-2302 5.3 MEDIUM EPSS 0.00
Ecava Integraxor < 4.2.4502 - Information Disclosure
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
CWE-200 Apr 22, 2016
CVE-2016-2301 6.3 MEDIUM EPSS 0.00
Ecava Integraxor < 4.2.4502 - SQL Injection
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Apr 22, 2016
CVE-2016-2300 6.5 MEDIUM EPSS 0.00
Ecava Integraxor < 4.2.4502 - Authentication Bypass
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
CWE-287 Apr 22, 2016
CVE-2016-3977 5.5 MEDIUM EPSS 0.01
giflib 5.1.2 - Buffer Overflow
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.
CWE-119 Apr 21, 2016
CVE-2013-7449 6.5 MEDIUM EPSS 0.00
HexChat <2.10.2 - Man-In-The-Middle
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CWE-310 Apr 21, 2016
CVE-2016-3465 5.5 MEDIUM EPSS 0.00
Oracle Sun Solaris <11.3 - DoS
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors related to ZFS.
Apr 21, 2016
CVE-2016-3464 5.7 MEDIUM EPSS 0.00
Oracle FLEXCUBE <12.0.3 - Info Disclosure
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts.
Apr 21, 2016
CVE-2016-3463 6.1 MEDIUM EPSS 0.00
Oracle FLEXCUBE <12.0.3 - Info Disclosure
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.
Apr 21, 2016
CVE-2016-3462 5.5 MEDIUM EPSS 0.00
Oracle Sun Solaris 11.3 - DoS
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Network Configuration Service.
Apr 21, 2016
CVE-2016-3460 5.4 MEDIUM EPSS 0.00
Oracle PeopleSoft Products 9.2 - Info Disclosure
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to ePerformance.
Apr 21, 2016