CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2016-1334 5.3 MEDIUM EPSS 0.00
Cisco Small Business 500 Wireless Access Point <1.0.4.4 - RCE
Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.
CWE-20 Feb 17, 2016
CVE-2016-1333 6.5 MEDIUM EPSS 0.00
Cisco IOS <15.5(3)M, 15.6(1)T0a - DoS
Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.
CWE-399 Feb 17, 2016
CVE-2016-2072 6.1 MEDIUM EPSS 0.00
Citrix Netscaler - Security Feature Bypass
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CWE-254 Feb 17, 2016
CVE-2016-2046 6.1 MEDIUM EPSS 0.01
SOPHOS UTM <9.353 - XSS
Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CWE-79 Feb 17, 2016
CVE-2013-7447 6.5 MEDIUM EPSS 0.05
GTK+ <3.9.8 - DoS
Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, which triggers a large memory allocation.
Feb 17, 2016
CVE-2016-1153 6.5 MEDIUM EPSS 0.01
Cybozu Office <10.3.0 - DoS
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.
CWE-20 Feb 17, 2016
CVE-2016-1152 5.4 MEDIUM EPSS 0.00
Cybozu Office 9.9.0-10.3.0 - Auth Bypass
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2015-8486.
CWE-264 Feb 17, 2016
CVE-2016-1150 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.
CWE-79 Feb 17, 2016
CVE-2016-1149 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1150.
CWE-79 Feb 17, 2016
CVE-2015-8489 6.5 MEDIUM EPSS 0.01
Cybozu Office <10.3.0 - DoS
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.
CWE-20 Feb 17, 2016
CVE-2015-8488 4.3 MEDIUM EPSS 0.00
Cybozu Office 10.3.0 - Info Disclosure
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.
CWE-200 Feb 17, 2016
CVE-2015-8487 4.3 MEDIUM EPSS 0.00
Cybozu Office <10.3 - CSRF
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
CWE-200 Feb 17, 2016
CVE-2015-8486 5.4 MEDIUM EPSS 0.00
Cybozu Office 9.9.0-10.3.0 - Auth Bypass
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.
CWE-264 Feb 17, 2016
CVE-2015-8485 5.4 MEDIUM EPSS 0.00
Cybozu Office 9.9.0-10.3.0 - Auth Bypass
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.
CWE-264 Feb 17, 2016
CVE-2015-8484 5.4 MEDIUM EPSS 0.00
Cybozu Office <10.3.0 - Auth Bypass
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.
CWE-264 Feb 17, 2016
CVE-2015-7798 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2016-1149, and CVE-2016-1150.
CWE-79 Feb 17, 2016
CVE-2015-7797 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
CWE-79 Feb 17, 2016
CVE-2015-7796 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
CWE-79 Feb 17, 2016
CVE-2015-7795 6.1 MEDIUM EPSS 0.01
Cybozu Office 9.0.0-10.3.0 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
CWE-79 Feb 17, 2016
CVE-2016-2388 5.3 MEDIUM KEV 3 PoCs Analysis EPSS 0.62
SAP Netweaver Application Server Java < 7.50 - Information Disclosure
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
CWE-200 Feb 16, 2016