CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2015-8524 6.1 MEDIUM EPSS 0.00
IBM Business Process Manager <8.5.0.2-8.5.6.2 - XSS
Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 29, 2016
CVE-2015-7491 5.4 MEDIUM EPSS 0.00
IBM WebSphere Portal <8.0.0.1 CF20, <8.5.0.0 CF09 - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 29, 2016
CVE-2015-7457 6.1 MEDIUM EPSS 0.00
IBM WebSphere Portal <8.0.0.1 CF20, <8.5.0.0 CF09 - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 29, 2016
CVE-2016-2532 5.9 MEDIUM EPSS 0.01
Wireshark - Memory Corruption
The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.
CWE-119 Feb 28, 2016
CVE-2016-2531 5.9 MEDIUM EPSS 0.01
Wireshark - Memory Corruption
Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a different vulnerability than CVE-2016-2530.
CWE-119 Feb 28, 2016
CVE-2016-2530 5.9 MEDIUM EPSS 0.01
Wireshark - Memory Corruption
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet, a different vulnerability than CVE-2016-2531.
CWE-119 Feb 28, 2016
CVE-2016-2529 5.5 MEDIUM EPSS 0.00
Wireshark - Memory Corruption
The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
CWE-119 Feb 28, 2016
CVE-2016-2528 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
CWE-20 Feb 28, 2016
CVE-2016-2527 5.5 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.
CWE-20 Feb 28, 2016
CVE-2016-2526 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
CWE-20 Feb 28, 2016
CVE-2016-2525 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.
CWE-20 Feb 28, 2016
CVE-2016-2524 5.9 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-20 Feb 28, 2016
CVE-2016-2523 5.9 MEDIUM EPSS 0.05
Wireshark - Resource Management Error
The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
CWE-399 Feb 28, 2016
CVE-2016-2522 5.9 MEDIUM EPSS 0.00
Wireshark - Memory Corruption
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
CWE-119 Feb 28, 2016
CVE-2016-1342 5.3 MEDIUM EPSS 0.00
Cisco FirePOWER Mgmt Ctr <6.0.0.1 - Info Disclosure
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
CWE-200 Feb 26, 2016
CVE-2016-0763 6.3 MEDIUM EPSS 0.00
Apache Tomcat <7.0.68, <8.0.31, <9.0.0.M3 - Privilege Escalation
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
CWE-264 Feb 25, 2016
CVE-2016-0706 4.3 MEDIUM EPSS 0.02
Apache Tomcat <6.0.45-9.0.0.M2 - Auth Bypass
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.
CWE-200 Feb 25, 2016
CVE-2015-5345 5.3 MEDIUM EPSS 0.15
Apache Tomcat <6.0.45-9.0.0.M2 - Info Disclosure
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
CWE-22 Feb 25, 2016
CVE-2015-5174 4.3 MEDIUM EPSS 0.04
Apache Tomcat < 8.0.27 - Path Traversal
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.
CWE-22 Feb 25, 2016
CVE-2016-1157 6.1 MEDIUM EPSS 0.00
Script* Log-Chat <2.0 - XSS
Cross-site scripting (XSS) vulnerability in log_chat.cgi in Script* Log-Chat before 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 23, 2016