CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
110,849 results Clear all
CVE-2015-3275 6.1 MEDIUM EPSS 0.00
Moodle <2.6.11, <2.7.9, <2.8.7, <2.9.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
CWE-79 Feb 22, 2016
CVE-2015-3274 6.1 MEDIUM EPSS 0.00
Moodle <2.9.1 - XSS
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.
CWE-79 Feb 22, 2016
CVE-2015-3273 4.3 MEDIUM EPSS 0.00
Moodle 2.9.x <2.9.1 - Auth Bypass
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.
CWE-264 Feb 22, 2016
CVE-2016-1628 6.3 MEDIUM EPSS 0.01
OpenJPEG <48.0.2564.109 - RCE
pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 image in a PDF document, related to the opj_pi_next_rpcl, opj_pi_next_pcrl, and opj_pi_next_cprl functions.
CWE-119 Feb 21, 2016
CVE-2016-2045 5.4 MEDIUM EPSS 0.00
phpMyAdmin <4.5.4 - XSS
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.
CWE-79 Feb 20, 2016
CVE-2016-2044 5.3 MEDIUM EPSS 0.00
phpMyAdmin <4.5.4 - Info Disclosure
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CWE-200 Feb 20, 2016
CVE-2016-2043 5.4 MEDIUM EPSS 0.00
phpMyAdmin <4.4.15.3, <4.5.4 - XSS
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.
CWE-79 Feb 20, 2016
CVE-2016-2042 5.3 MEDIUM EPSS 0.01
phpMyAdmin <4.4.15.3-4.5.4 - Info Disclosure
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
CWE-200 Feb 20, 2016
CVE-2016-2040 5.4 MEDIUM EPSS 0.00
phpMyAdmin <4.0.10.13, <4.4.15.3, <4.5.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.
CWE-79 Feb 20, 2016
CVE-2016-2039 5.3 MEDIUM EPSS 0.00
phpMyAdmin <4.0.10.13, <4.4.15.3, <4.5.4 - CSRF
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
CWE-200 Feb 20, 2016
CVE-2016-2038 5.3 MEDIUM 1 Writeup EPSS 0.01
phpMyAdmin <4.0.10.13, <4.4.15.3, <4.5.4 - Info Disclosure
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CWE-200 Feb 20, 2016
CVE-2016-1156 5.7 MEDIUM EPSS 0.00
LINE <4.3.0.724-<4.3.1 - DoS
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.
CWE-20 Feb 19, 2016
CVE-2015-7769 6.3 MEDIUM EPSS 0.01
baserCMS <3.0.9 - Command Injection
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
CWE-78 Feb 19, 2016
CVE-2016-2271 5.5 MEDIUM EPSS 0.00
Xen - Denial of Service
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.
Feb 19, 2016
CVE-2016-2270 6.8 MEDIUM EPSS 0.00
Debian Linux < 4.6.1 - Improper Input Validation
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
CWE-20 Feb 19, 2016
CVE-2016-2509 5.3 MEDIUM EPSS 0.00
Belden Hirschmann Firmware < 09.0.05 - Information Disclosure
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.
CWE-200 Feb 18, 2016
CVE-2016-1987 5.9 MEDIUM EPSS 0.02
HPE IPFilter A.11.31.18.21 - DoS
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
CWE-20 Feb 18, 2016
CVE-2015-5970 5.3 MEDIUM EPSS 0.01
Novell ZENworks <11.4 - XPath Injection
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
CWE-94 Feb 18, 2016
CVE-2015-8287 5.3 MEDIUM EPSS 0.00
Swann SRNVW-470LCD <0114 - Info Disclosure
Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL.
Feb 18, 2016
CVE-2016-2398 6.5 MEDIUM EPSS 0.01
Comcast Xfinity Home Security System - Security Feature Bypass
Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions.
CWE-254 Feb 17, 2016