CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2016-2387 6.1 MEDIUM EPSS 0.00
SAP Netweaver - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or (2) interface parameter to ProxyServer/register, aka SAP Security Note 2220571.
CWE-79 Feb 16, 2016
CVE-2016-0753 5.3 MEDIUM EPSS 0.02
Ruby on Rails <4.1.14.1, <4.2.5.1, <5.0.0.beta1.1 - Info Disclosure
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Feb 16, 2016
CVE-2015-7580 6.1 MEDIUM EPSS 0.00
rails-html-sanitizer <1.0.3 - XSS
Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
CWE-79 Feb 16, 2016
CVE-2015-7579 6.1 MEDIUM EPSS 0.00
rails-html-sanitizer 1.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.
CWE-79 Feb 16, 2016
CVE-2015-7578 6.1 MEDIUM EPSS 0.00
rails-html-sanitizer <1.0.3 - XSS
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.
CWE-79 Feb 16, 2016
CVE-2015-7577 5.3 MEDIUM EPSS 0.01
Ruby on Rails <5.0.0.beta1.1 - RCE
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
CWE-284 Feb 16, 2016
CVE-2016-1331 6.1 MEDIUM EPSS 0.00
Cisco Emergency Responder 11.5(0.99833.5) - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
CWE-79 Feb 15, 2016
CVE-2016-1330 6.5 MEDIUM EPSS 0.00
Cisco IOS <15.2(4)E - DoS
Cisco IOS 15.2(4)E on Industrial Ethernet 2000 devices allows remote attackers to cause a denial of service (device reload) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuy27746.
CWE-399 Feb 15, 2016
CVE-2016-1321 5.8 MEDIUM EPSS 0.00
Cisco Universal Small Cell - Info Disclosure
Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.
CWE-200 Feb 15, 2016
CVE-2016-0232 4.3 MEDIUM EPSS 0.00
IBM FTM <3.0.0 - Info Disclosure
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.
CWE-200 Feb 15, 2016
CVE-2016-0231 4.3 MEDIUM EPSS 0.00
IBM FTM <3.0.0 - Info Disclosure
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.
CWE-200 Feb 15, 2016
CVE-2016-0747 5.3 MEDIUM EPSS 0.33
nginx <1.8.1, <1.9.10 - DoS
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
CWE-400 Feb 15, 2016
CVE-2016-2314 4.9 MEDIUM EPSS 0.00
Huawei Mt882 Firmware - Denial of Service
GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands.
CWE-17 Feb 15, 2016
CVE-2015-8797 6.1 MEDIUM EPSS 0.02
Apache Solr < 5.3 - XSS
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
CWE-79 Feb 15, 2016
CVE-2015-8796 6.1 MEDIUM EPSS 0.03
Apache Solr < 5.2.1 - XSS
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
CWE-79 Feb 15, 2016
CVE-2015-8795 6.1 MEDIUM EPSS 0.03
Apache Solr < 5.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
CWE-79 Feb 15, 2016
CVE-2015-8531 6.1 MEDIUM EPSS 0.00
IBM Security Access Manager for Web <9.0.0.1-8.0.1.3 - XSS
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 15, 2016
CVE-2015-7492 5.4 MEDIUM EPSS 0.00
IBM InfoSphere MDM <11.5 - XSS
Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 15, 2016
CVE-2015-7444 5.3 MEDIUM EPSS 0.00
IBM WebSphere Commerce Enterprise <7.0.0.9 - Info Disclosure
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.
CWE-200 Feb 15, 2016
CVE-2015-7398 5.4 MEDIUM EPSS 0.00
IBM Emptoris Contract Management - XSS
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 15, 2016