CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
110,849 results Clear all
CVE-2016-2424 5.5 MEDIUM EPSS 0.00
Google Android - Improper Input Validation
server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loop) via a crafted application, aka internal bug 26513719.
CWE-20 Apr 18, 2016
CVE-2016-2423 6.1 MEDIUM EPSS 0.00
Google Android - Access Control
server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.
CWE-264 Apr 18, 2016
CVE-2016-2421 6.1 MEDIUM EPSS 0.00
Google Android - Access Control
Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.
CWE-264 Apr 18, 2016
CVE-2016-2415 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to obtain sensitive information via a crafted application that triggers a spoofed response to a GET request, aka internal bug 26488455.
CWE-200 Apr 18, 2016
CVE-2016-2414 6.2 MEDIUM EPSS 0.01
Google Android - Improper Input Validation
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.
CWE-20 Apr 18, 2016
CVE-2016-2411 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Google Android - Improper Input Validation
A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.
CWE-20 Apr 18, 2016
CVE-2016-3144 5.4 MEDIUM EPSS 0.00
Fourkitchens Block Class - XSS
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
CWE-79 Apr 15, 2016
CVE-2015-7676 5.4 MEDIUM EPSS 0.00
Ipswitch MOVEit File Transfer <8.1 - XSS
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
CWE-79 Apr 15, 2016
CVE-2016-3961 5.5 MEDIUM EPSS 0.00
Xen & Linux Kernel <4.5.x - DoS
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
CWE-20 Apr 15, 2016
CVE-2016-2212 5.3 MEDIUM EPSS 0.00
Magento < 1.9.2.2 - Information Disclosure
The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Community Edition before 1.9.2.3 allows remote attackers to obtain sensitive order information via the order_id in a JSON object in the data parameter in an RSS feed request to index.php/rss/order/status.
CWE-200 Apr 15, 2016
CVE-2016-1273 5.9 MEDIUM EPSS 0.00
Juniper Junos OS <13.2X51-D40-14.x<14.1X53-D30-15.x<15.1X53-D20 - I...
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
CWE-310 Apr 15, 2016
CVE-2016-1267 6.7 MEDIUM EPSS 0.00
Juniper Junos OS < various - Info Disclosure
Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R3-S4, 15.1 before 15.1F2, or 15.1R2, 15.1X49 before 15.1X49-D20, and 16.1 before 16.1R1 allows local users to read, delete, or modify arbitrary files via unspecified vectors.
CWE-362 Apr 15, 2016
CVE-2015-8677 6.5 MEDIUM EPSS 0.00
Huawei S5300ei Firmware < v200r003sph011 - Resource Management Error
Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00 before V200R006SPH002; S9300, S7700, and S9700 Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH009, and V200R006C00 before V200R006SPH003; S5720HI and S5720EI Campus series switches with software V200R006C00 before V200R006SPH002; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote authenticated users to cause a denial of service (memory consumption and device restart) by logging in and out of the (1) HTTPS or (2) SFTP server, related to SSL session information.
CWE-399 Apr 14, 2016
CVE-2015-8336 4.3 MEDIUM EPSS 0.00
Huawei FusionCompute <V100R005C10SPC700 - Info Disclosure
Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role and permission" information via unspecified vectors.
CWE-200 Apr 14, 2016
CVE-2015-5247 6.5 MEDIUM EPSS 0.00
libvirt <1.2.20 - DoS
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
CWE-284 Apr 14, 2016
CVE-2011-4600 5.9 MEDIUM EPSS 0.00
Canonical Ubuntu Linux - Improper Access Control
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
CWE-284 Apr 14, 2016
CVE-2016-4016 6.1 MEDIUM EPSS 0.00
SAP MII 15 - XSS
Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inject arbitrary web script or HTML via the title parameter to webdynpro/resources/sap.com/xapps~xmii~ui~admin~navigation/NavigationApplication, aka SAP Security Note 2201295.
CWE-79 Apr 14, 2016
CVE-2016-3079 6.1 MEDIUM EPSS 0.00
Redhat Satellite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
CWE-79 Apr 14, 2016
CVE-2016-2103 6.1 MEDIUM EPSS 0.00
Redhat Satellite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.
CWE-79 Apr 14, 2016
CVE-2015-0284 5.4 MEDIUM EPSS 0.00
Redhat Satellite - XSS
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
CWE-79 Apr 14, 2016