CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2016-2316 5.9 MEDIUM EPSS 0.01
Fedora - Integer Underflow
chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set to a value greater than 1245, allows remote attackers to cause a denial of service (file descriptor consumption) via vectors related to large retransmit timeout values.
CWE-191 Feb 22, 2016
CVE-2016-2232 6.5 MEDIUM EPSS 0.08
Digium Asterisk - Denial of Service
Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.
Feb 22, 2016
CVE-2016-2037 6.5 MEDIUM EPSS 0.19
cpio <2.11 - DoS
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
CWE-119 Feb 22, 2016
CVE-2016-0725 6.1 MEDIUM EPSS 0.01
Moodle <2.8.10-3.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.
CWE-79 Feb 22, 2016
CVE-2016-0724 4.3 MEDIUM EPSS 0.01
Moodle <3.0.2 - Info Disclosure
The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request.
CWE-200 Feb 22, 2016
CVE-2015-5342 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.11, <2.8.9, <2.9.3 - Auth Bypass
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.
CWE-264 Feb 22, 2016
CVE-2015-5341 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.11, <2.8.9, <2.9.3 - Privilege Escalation
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.
CWE-200 Feb 22, 2016
CVE-2015-5340 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11-2.9.3 - Info Disclosure
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.
CWE-200 Feb 22, 2016
CVE-2015-5339 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.11, <2.8.9, <2.9.3 - Info Disclosure
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.
CWE-200 Feb 22, 2016
CVE-2015-5337 6.1 MEDIUM EPSS 0.00
Moodle <2.6.11-2.9.3 - XSS
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
CWE-79 Feb 22, 2016
CVE-2015-5336 5.4 MEDIUM EPSS 0.00
Moodle <2.6.11-2.9.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
CWE-79 Feb 22, 2016
CVE-2015-5335 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11-2.9.3 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.
CWE-352 Feb 22, 2016
CVE-2015-5332 6.8 MEDIUM EPSS 0.01
Moodle <2.8.9, <2.9.3 - DoS
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
CWE-399 Feb 22, 2016
CVE-2015-5331 4.3 MEDIUM EPSS 0.00
Moodle 2.9.x <2.9.3 - Auth Bypass
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
CWE-254 Feb 22, 2016
CVE-2015-5272 4.3 MEDIUM EPSS 0.00
Moodle 2.7.x <2.7.10 - Privilege Escalation
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
CWE-264 Feb 22, 2016
CVE-2015-5269 5.4 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - XSS
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
CWE-79 Feb 22, 2016
CVE-2015-5268 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Info Disclosure
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
CWE-200 Feb 22, 2016
CVE-2015-5266 6.8 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Privilege Escalation
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.
CWE-264 Feb 22, 2016
CVE-2015-5265 4.3 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Privilege Escalation
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
CWE-264 Feb 22, 2016
CVE-2015-5264 5.4 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.10, <2.8.8, <2.9.2 - Auth Bypass
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
CWE-264 Feb 22, 2016