CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-4991 4.0 MEDIUM EPSS 0.00
IBM Spss Modeler - Information Disclosure
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.
CWE-200 Feb 15, 2016
CVE-2015-4957 5.4 MEDIUM EPSS 0.00
IBM Qradar Security Information And Event Manager - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Feb 15, 2016
CVE-2015-3197 5.9 MEDIUM 1 PoC Analysis EPSS 0.22
OpenSSL <1.0.1r-1.0.2f - Info Disclosure
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
CWE-310 Feb 15, 2016
CVE-2015-2008 4.4 MEDIUM EPSS 0.00
IBM Qradar Security Information And E... - Improper Access Control
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
CWE-284 Feb 15, 2016
CVE-2015-2005 5.3 MEDIUM EPSS 0.00
IBM Qradar Security Information And E... - Information Disclosure
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
CWE-200 Feb 15, 2016
CVE-2016-1626 4.3 MEDIUM EPSS 0.01
OpenJPEG - DoS
The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
CWE-119 Feb 14, 2016
CVE-2016-1625 4.3 MEDIUM EPSS 0.01
Google Chrome <48.0.2564.109 - CSRF
The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc.
CWE-264 Feb 14, 2016
CVE-2016-1523 6.5 MEDIUM EPSS 0.01
Mozilla Firefox <43.0 & ESR 38.x <38.6.1 - DoS
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
Feb 13, 2016
CVE-2016-0866 6.1 MEDIUM EPSS 0.00
Tollgrade SmartGrid LightHouse SMS <5.1 & 4.1.0-16 - XSS
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 13, 2016
CVE-2016-0864 5.3 MEDIUM EPSS 0.00
Tollgrade SMS <5.1 - Info Disclosure
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
CWE-200 Feb 13, 2016
CVE-2015-8631 6.5 MEDIUM EPSS 0.02
MIT Kerberos 5 < 1.13.4 - Resource Leak
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
CWE-772 Feb 13, 2016
CVE-2015-8629 5.3 MEDIUM EPSS 0.02
MIT Kerberos 5 < 1.13.4 - Out-of-Bounds Read
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
CWE-125 Feb 13, 2016
CVE-2016-2073 6.5 MEDIUM EPSS 0.01
Xmlsoft Libxml2 < 2.9.4 - Memory Corruption
The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
CWE-119 Feb 12, 2016
CVE-2016-1324 5.3 MEDIUM EPSS 0.00
Cisco Spark 2015-06 - DoS
The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125.
CWE-264 Feb 12, 2016
CVE-2016-1323 4.3 MEDIUM EPSS 0.00
Cisco Spark 2015-06 - Info Disclosure
The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048.
CWE-200 Feb 12, 2016
CVE-2016-1320 6.7 MEDIUM EPSS 0.00
Cisco Prime Collaboration <11.0 - Command Injection
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
CWE-78 Feb 12, 2016
CVE-2016-0882 5.4 MEDIUM EPSS 0.00
EMC Documentum xCP <2.1-2.2 - Info Disclosure
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Feb 12, 2016
CVE-2016-0881 6.5 MEDIUM EPSS 0.00
EMC Documentum xCP <2.1-2.2 - SQL Injection
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.
CWE-74 Feb 12, 2016
CVE-2016-0955 6.1 MEDIUM EPSS 0.00
Adobe Experience Manager 6.1.0 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
CWE-79 Feb 10, 2016
CVE-2016-0950 5.3 MEDIUM EPSS 0.01
Adobe Connect <9.5.2 - XSS
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
CWE-254 Feb 10, 2016