CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2015-2344 5.4 MEDIUM EPSS 0.00
Vmware Vrealize Automation - XSS
Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 16, 2016
CVE-2016-1731 5.9 MEDIUM EPSS 0.00
Apple Software Update <2.2 - Info Disclosure
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
CWE-310 Mar 14, 2016
CVE-2016-0262 5.4 MEDIUM EPSS 0.00
IBM Maximo Asset Management <7.1.1.3-7.5.0.9-7.6.0.3 - XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 14, 2016
CVE-2016-0222 4.3 MEDIUM EPSS 0.00
IBM Maximo Asset Mgmt <7.6.0.3 - Auth Bypass
IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.
CWE-284 Mar 14, 2016
CVE-2016-0771 5.9 MEDIUM EPSS 0.06
Samba <4.1.23-4.4.0rc4 - DoS
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
CWE-119 Mar 13, 2016
CVE-2015-7560 6.5 MEDIUM EPSS 0.04
Samba <4.1.23, <4.2.9, <4.3.6, <4.4.0rc4 - Privilege Escalation
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
CWE-284 Mar 13, 2016
CVE-2016-1976 5.5 MEDIUM EPSS 0.01
Mozilla Firefox <45.0 - Use After Free
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Mar 13, 2016
CVE-2016-1975 6.3 MEDIUM EPSS 0.01
Mozilla Firefox <45.0 - Memory Corruption
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CWE-362 Mar 13, 2016
CVE-2016-1967 6.5 MEDIUM EPSS 0.00
Mozilla Firefox <45.0 - Info Disclosure
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.
CWE-200 Mar 13, 2016
CVE-2016-1965 4.3 MEDIUM EPSS 0.01
Mozilla Firefox <45.0 - Info Disclosure
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
CWE-254 Mar 13, 2016
CVE-2016-1958 4.3 MEDIUM EPSS 0.01
Mozilla Firefox <45.0 - Firefox
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
CWE-254 Mar 13, 2016
CVE-2016-1957 4.3 MEDIUM EPSS 0.00
Mozilla Firefox <45.0, Firefox ESR <38.7 - Memory Consumption
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
CWE-119 Mar 13, 2016
CVE-2016-1956 6.5 MEDIUM EPSS 0.00
Mozilla Firefox <45.0 - Memory Corruption
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
CWE-399 Mar 13, 2016
CVE-2016-1955 4.3 MEDIUM EPSS 0.01
Mozilla Firefox <45.0 - CSRF
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
CWE-200 Mar 13, 2016
CVE-2016-0832 6.1 MEDIUM EPSS 0.00
Android <LMY49H - Privilege Escalation
Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.
CWE-254 Mar 12, 2016
CVE-2016-0831 5.5 MEDIUM EPSS 0.00
Android <5.1.1 LMY49H & <6 - Info Disclosure
The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25778215.
CWE-200 Mar 12, 2016
CVE-2016-0830 6.5 MEDIUM EPSS 0.00
Android <6.x - DoS
btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maximum size of a configuration file, aka internal bug 26071376.
CWE-119 Mar 12, 2016
CVE-2016-0825 5.3 MEDIUM EPSS 0.00
Android 6.0.1 - Info Disclosure
The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 20860039.
CWE-254 Mar 12, 2016
CVE-2016-0824 5.3 MEDIUM EPSS 0.00
Android 6.x - Info Disclosure
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.
CWE-254 Mar 12, 2016
CVE-2016-0823 4.0 MEDIUM EPSS 0.00
Linux kernel <3.19.3 - Info Disclosure
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
CWE-200 Mar 12, 2016