CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2016-1770 6.5 MEDIUM EPSS 0.00
Apple OS X <10.11.4 - Auth Bypass
The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL.
CWE-284 Mar 24, 2016
CVE-2016-1764 4.3 MEDIUM 2 PoCs Analysis EPSS 0.09
Apple OS X <10.11.4 - Info Disclosure
The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.
CWE-200 Mar 24, 2016
CVE-2016-1752 5.5 MEDIUM EPSS 0.00
Apple - DoS
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to cause a denial of service via a crafted app.
CWE-20 Mar 24, 2016
CVE-2016-1745 5.5 MEDIUM EPSS 0.00
Apple OS X <10.11.4 - DoS
IOFireWireFamily in Apple OS X before 10.11.4 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
Mar 24, 2016
CVE-2016-1737 6.3 MEDIUM EPSS 0.01
Carbon <10.11.4 - Memory Corruption
Carbon in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dfont file.
CWE-119 Mar 24, 2016
CVE-2016-1734 6.8 MEDIUM 1 PoC Analysis EPSS 0.00
Apple <9.3-10.11.4 - RCE/DoS
AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.
CWE-119 Mar 24, 2016
CVE-2016-1732 5.5 MEDIUM EPSS 0.00
Apple OS X <10.11.4 - Info Disclosure/DoS
AppleRAID in Apple OS X before 10.11.4 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.
CWE-119 Mar 24, 2016
CVE-2016-1599 6.1 MEDIUM EPSS 0.00
NetIQ SSRP <3.3.1 HF2 - XSS
Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 24, 2016
CVE-2009-2197 4.3 MEDIUM EPSS 0.00
Apple Safari <9.1 - XSS
Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog.
CWE-19 Mar 24, 2016
CVE-2016-3116 6.4 MEDIUM 2 PoCs Analysis EPSS 0.28
Dropbear SSH <2016.72 - Auth Bypass
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data.
Mar 22, 2016
CVE-2016-3115 6.4 MEDIUM 1 PoC Analysis EPSS 0.43
OpenSSH <7.2p2 - CRLF Injection
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Mar 22, 2016
CVE-2015-7454 4.3 MEDIUM EPSS 0.00
IBM WebSphere Process Server <7.0.0.5 - Auth Bypass
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
CWE-264 Mar 21, 2016
CVE-2016-0283 6.1 MEDIUM EPSS 0.00
IBM WAS Liberty Profile <8.5.5.9 - XSS
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 19, 2016
CVE-2016-2287 6.1 MEDIUM EPSS 0.00
Xzeres 442sr OS - XSS
Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2016
CVE-2015-2286 6.5 MEDIUM 1 Writeup EPSS 0.00
Open Edx < 2015-01-27 - Information Disclosure
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.
CWE-200 Mar 19, 2016
CVE-2016-1994 6.5 MEDIUM EPSS 0.00
HPE System Management Homepage <7.5.4 - Info Disclosure
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CWE-200 Mar 18, 2016
CVE-2015-5968 6.1 MEDIUM EPSS 0.00
Novell Filr <1.2 - XSS
Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 18, 2016
CVE-2016-1992 6.5 MEDIUM EPSS 0.00
HPE ArcSight ESM <6.8c-6.9.1 - Info Disclosure
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
CWE-200 Mar 17, 2016
CVE-2016-2846 6.5 MEDIUM EPSS 0.00
Siemens Simatic S7 Cpu 1200 Firmware < 3.0.2 - Security Feature Bypass
Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program block" protection mechanism via unspecified vectors.
CWE-254 Mar 16, 2016
CVE-2016-2075 5.4 MEDIUM EPSS 0.00
Vmware Vrealize Business Advanced And Enterprise - XSS
Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 16, 2016