CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
110,849 results Clear all
CVE-2015-0265 6.1 MEDIUM EPSS 0.02
Apache Ranger < 0.4.0 - XSS
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.
CWE-79 Apr 11, 2016
CVE-2016-3676 6.4 MEDIUM EPSS 0.00
Huawei E3276s - Man-in-the-Middle
Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to a fake network.
CWE-254 Apr 11, 2016
CVE-2016-2163 6.1 MEDIUM EPSS 0.03
Apache Openmeetings < 3.1.0 - XSS
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
CWE-79 Apr 11, 2016
CVE-2016-0784 6.5 MEDIUM 1 PoC Analysis EPSS 0.06
Apache OpenMeetings <3.1.1 - Path Traversal
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.
CWE-22 Apr 11, 2016
CVE-2016-0712 6.1 MEDIUM EPSS 0.03
Apache Jetspeed <2.3.1 - XSS
Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.
CWE-79 Apr 11, 2016
CVE-2016-0711 6.1 MEDIUM EPSS 0.03
Apache Jetspeed <2.3.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
CWE-79 Apr 11, 2016
CVE-2016-3984 5.1 MEDIUM 1 PoC Analysis EPSS 0.00
McAfee - Multiple Vulns
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
CWE-284 Apr 08, 2016
CVE-2016-3963 5.3 MEDIUM 1 PoC Analysis EPSS 0.06
Siemens SCALANCE S613 - DoS
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443.
Apr 08, 2016
CVE-2016-1375 6.1 MEDIUM EPSS 0.00
Cisco IP Interoperability and Collaboration System 4.10(1) - XSS
Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy12339.
CWE-79 Apr 08, 2016
CVE-2016-1180 6.1 MEDIUM EPSS 0.00
EC-CUBE 2.13.x - XSS
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 08, 2016
CVE-2015-5969 6.2 MEDIUM EPSS 0.00
mysql-community-server <5.6.28-2.17.1, mariadb <10.0.22-2.21.2 - In...
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by listing a process and its arguments.
CWE-200 Apr 08, 2016
CVE-2016-3978 6.1 MEDIUM NUCLEI EPSS 0.06
FortiOS <5.0.13-5.2.3-5.4.0 - CSRF
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
CWE-79 Apr 08, 2016
CVE-2016-2789 6.1 MEDIUM EPSS 0.00
Citrix Xenmobile Server - XSS
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 07, 2016
CVE-2016-2097 5.3 MEDIUM EPSS 0.02
Rails < 3.2.22.1 - Path Traversal
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.
CWE-22 Apr 07, 2016
CVE-2016-0790 5.3 MEDIUM EPSS 0.00
Jenkins <1.650-1.642.2 - Info Disclosure
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
CWE-254 Apr 07, 2016
CVE-2016-0789 6.1 MEDIUM EPSS 0.00
Jenkins <1.650-1.642.2 - CRLF Injection
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CWE-20 Apr 07, 2016
CVE-2016-2511 6.1 MEDIUM EPSS 0.01
Debian Linux < 2.3.3 - XSS
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
CWE-79 Apr 07, 2016
CVE-2015-2774 5.9 MEDIUM EPSS 0.01
Erlang/otp < 18.0 - Information Disclosure
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
CWE-200 Apr 07, 2016
CVE-2015-8679 5.5 MEDIUM EPSS 0.00
Huawei Mate S Firmware - Improper Access Control
The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allow attackers to cause a denial of service (system crash) via a crafted application, which triggers an invalid memory access.
CWE-284 Apr 07, 2016
CVE-2016-3975 6.1 MEDIUM EPSS 0.01
SAP NetWeaver AS Java <7.6 - XSS
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note 2238375.
CWE-79 Apr 07, 2016