CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2016-1358 6.4 MEDIUM EPSS 0.00
Cisco Prime Infrastructure <3.1 - XXE
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.
CWE-119 Mar 03, 2016
CVE-2016-1357 5.3 MEDIUM EPSS 0.00
Cisco Policy Suite <7.5.0 - Auth Bypass
The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut85211.
CWE-200 Mar 03, 2016
CVE-2016-1288 5.3 MEDIUM EPSS 0.00
Cisco AsyncOS <8.5.3-051 & 9.x <9.0.0-485 - DoS
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
CWE-20 Mar 03, 2016
CVE-2016-0227 5.4 MEDIUM EPSS 0.00
IBM BPM <8.0.1.3, <8.5.0.2, <8.5.6.2 - XSS
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 03, 2016
CVE-2016-0702 5.1 MEDIUM 1 PoC Analysis EPSS 0.00
OpenSSL <1.0.1s-1.0.2g - Info Disclosure
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.
CWE-200 Mar 03, 2016
CVE-2016-1355 6.1 MEDIUM EPSS 0.00
Cisco FireSIGHT System Software 6.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy41687.
CWE-79 Mar 03, 2016
CVE-2016-1354 6.1 MEDIUM EPSS 0.00
Cisco UCDM <8.1.1 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176.
CWE-79 Mar 03, 2016
CVE-2016-2279 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Rockwellautomation Compactlogix 1769-l16er-bb1b Firmware - XSS
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 02, 2016
CVE-2016-0704 5.9 MEDIUM EPSS 0.06
OpenSSL <1.0.2a - Info Disclosure
An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.
CWE-200 Mar 02, 2016
CVE-2016-0703 5.9 MEDIUM EPSS 0.04
OpenSSL <1.0.2a - Info Disclosure
The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.
CWE-200 Mar 02, 2016
CVE-2016-0800 5.9 MEDIUM 1 PoC Analysis EPSS 0.90
OpenSSL <1.0.1s, 1.0.2 before 1.0.2g - RCE
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
CWE-310 Mar 01, 2016
CVE-2016-2562 6.8 MEDIUM EPSS 0.00
Phpmyadmin < 4.5.5.1 - Improper Input Validation
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
CWE-20 Mar 01, 2016
CVE-2016-2561 5.4 MEDIUM EPSS 0.01
Phpmyadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.
CWE-79 Mar 01, 2016
CVE-2016-2560 6.1 MEDIUM EPSS 0.01
Phpmyadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.
CWE-79 Mar 01, 2016
CVE-2016-2559 5.4 MEDIUM EPSS 0.00
Phpmyadmin < 4.5.5.1 - XSS
Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.
CWE-79 Mar 01, 2016
CVE-2016-1353 5.3 MEDIUM EPSS 0.00
Cisco Videoscape Distribution Suite - DoS
The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN packets, aka Bug ID CSCuy45136.
CWE-399 Mar 01, 2016
CVE-2016-0245 5.4 MEDIUM EPSS 0.00
IBM WebSphere Portal <8.0.0.1 CF20 & 8.5.x <8.5.0.0 CF10 - Info Dis...
The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Feb 29, 2016
CVE-2016-0244 6.1 MEDIUM EPSS 0.00
IBM WebSphere Portal <8.5.0.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.
CWE-79 Feb 29, 2016
CVE-2016-0243 6.1 MEDIUM EPSS 0.00
IBM WebSphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.
CWE-79 Feb 29, 2016
CVE-2016-0225 4.9 MEDIUM EPSS 0.00
IBM WebSphere Commerce <7.0.0.9 - Info Disclosure
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
CWE-284 Feb 29, 2016