CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
110,849 results Clear all
CVE-2016-0407 6.5 MEDIUM EPSS 0.00
Oracle PeopleSoft <9.2 - Info Disclosure
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration.
Apr 21, 2016
CVE-2015-6479 4.3 MEDIUM EPSS 0.00
Sierra Wireless ALEOS <4.4.2 - Info Disclosure
ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.
Apr 21, 2016
CVE-2016-2202 5.5 MEDIUM EPSS 0.00
Symantec Altiris IT Management Suite < 7.6 - Access Control
The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors.
CWE-264 Apr 20, 2016
CVE-2015-7802 5.5 MEDIUM EPSS 0.00
OptiPNG <0.7.6 - DoS
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
CWE-119 Apr 20, 2016
CVE-2016-2390 5.9 MEDIUM EPSS 0.21
Squid < 3.5.13 - Improper Input Validation
The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.
CWE-20 Apr 19, 2016
CVE-2015-1776 6.2 MEDIUM EPSS 0.00
Apache Hadoop < 2.6.5 - Information Disclosure
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
CWE-200 Apr 19, 2016
CVE-2016-3688 6.5 MEDIUM EPSS 0.00
dotCMS <3.5 - SQL Injection
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
CWE-200 Apr 19, 2016
CVE-2016-3186 6.2 MEDIUM EPSS 0.01
Opensuse - Memory Corruption
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
CWE-119 Apr 19, 2016
CVE-2015-5479 6.5 MEDIUM EPSS 0.01
Libav <11.5 - DoS
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
CWE-189 Apr 19, 2016
CVE-2016-3971 4.8 MEDIUM EPSS 0.00
dotCMS <3.5.1 - XSS
Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to c/portal/layout.
CWE-79 Apr 18, 2016
CVE-2016-3941 5.5 MEDIUM EPSS 0.00
VLC media player <2.2.0 - Buffer Overflow
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
CWE-119 Apr 18, 2016
CVE-2016-4036 5.5 MEDIUM EPSS 0.00
quagga <0.99.23-2.6.1 - Info Disclosure
The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directory.
CWE-264 Apr 18, 2016
CVE-2016-3950 6.5 MEDIUM EPSS 0.00
Huawei AR3200 <V200R006C10SPC300 - DoS
Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted packets.
CWE-20 Apr 18, 2016
CVE-2016-1658 4.3 MEDIUM EPSS 0.01
Google Chrome <50.0.2661.75 - SSRF
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
CWE-284 Apr 18, 2016
CVE-2016-1657 4.3 MEDIUM EPSS 0.02
Google Chrome <50.0.2661.75 - Info Disclosure
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
CWE-254 Apr 18, 2016
CVE-2016-1654 6.5 MEDIUM EPSS 0.02
Google Chrome <50.0.2661.75 - DoS
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
CWE-20 Apr 18, 2016
CVE-2016-1652 6.1 MEDIUM EPSS 0.00
Google Chrome <50.0.2661.75 - XSS
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
CWE-79 Apr 18, 2016
CVE-2016-2427 5.5 MEDIUM EPSS 0.00
Bouncycastle Bc-java - Information Disclosure
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The vendor disputes the existence of this potential issue in Android, stating "This CVE was raised in error: it referred to the authentication tag size in GCM, whose default according to ASN.1 encoding (12 bytes) can lead to vulnerabilities. After careful consideration, it was decided that the insecure default value of 12 bytes was a default only for the encoding and not default anywhere else in Android, and hence no vulnerability existed.
CWE-200 Apr 18, 2016
CVE-2016-2426 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 26094635.
CWE-200 Apr 18, 2016
CVE-2016-2425 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted application, aka internal bugs 7154234 and 26989185.
CWE-200 Apr 18, 2016