CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-7680 5.3 MEDIUM EPSS 0.00
Ipswitch MOVEit DMZ <8.2 - Info Disclosure
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
CWE-200 Feb 10, 2016
CVE-2015-7679 6.1 MEDIUM EPSS 0.00
Ipswitch MOVEit Mobile <1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
CWE-79 Feb 10, 2016
CVE-2015-7677 4.3 MEDIUM EPSS 0.00
Ipswitch MOVEit DMZ <8.2 - Info Disclosure
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
CWE-200 Feb 10, 2016
CVE-2015-7675 6.5 MEDIUM EPSS 0.00
Ipswitch MOVEit DMZ <8.2, MOVEit Mobile <1.2.2 - Auth Bypass
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
CWE-200 Feb 10, 2016
CVE-2016-0080 4.3 MEDIUM EPSS 0.15
Microsoft Edge - Information Disclosure
Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass."
CWE-200 Feb 10, 2016
CVE-2016-0077 4.3 MEDIUM EPSS 0.09
Microsoft IE 9-11 & Edge - XSS
Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows remote attackers to spoof web sites via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
CWE-19 Feb 10, 2016
CVE-2016-0059 4.3 MEDIUM EPSS 0.14
Microsoft Internet Explorer - Information Disclosure
The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability."
CWE-200 Feb 10, 2016
CVE-2016-0050 5.3 MEDIUM EPSS 0.53
Microsoft Windows Server 2008 - Improper Input Validation
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."
CWE-20 Feb 10, 2016
CVE-2016-0049 6.2 MEDIUM 2 PoCs Analysis EPSS 0.04
Microsoft Windows 10 - Credentials Management
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
CWE-255 Feb 10, 2016
CVE-2016-0039 6.1 MEDIUM EPSS 0.01
Microsoft Sharepoint Foundation - XSS
Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
CWE-79 Feb 10, 2016
CVE-2016-1319 5.3 MEDIUM EPSS 0.00
Cisco - Info Disclosure
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.
CWE-200 Feb 09, 2016
CVE-2016-1318 6.1 MEDIUM EPSS 0.00
Cisco APIC-EM 1.1 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489.
CWE-79 Feb 09, 2016
CVE-2016-1317 4.3 MEDIUM EPSS 0.00
Cisco Unified Communications Manager 11.5 - Info Disclosure
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
CWE-200 Feb 09, 2016
CVE-2016-1316 5.3 MEDIUM EPSS 0.00
Cisco VCS X8.1-X8.7 - Info Disclosure
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362.
CWE-200 Feb 09, 2016
CVE-2016-2268 6.8 MEDIUM EPSS 0.00
Dell Secureworks - Cryptographic Issue
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-310 Feb 08, 2016
CVE-2016-2214 6.1 MEDIUM EPSS 0.00
Huawei Agile Controller-campus - XSS
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Feb 08, 2016
CVE-2016-2089 6.5 MEDIUM EPSS 0.01
Jasper - Improper Input Validation
The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.
CWE-20 Feb 08, 2016
CVE-2016-2048 5.5 MEDIUM EPSS 0.00
Django <1.9.2 - Auth Bypass
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.
CWE-284 Feb 08, 2016
CVE-2015-3251 4.9 MEDIUM EPSS 0.00
Apache CloudStack <4.5.2 - Info Disclosure
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
CWE-200 Feb 08, 2016
CVE-2016-2201 5.3 MEDIUM EPSS 0.02
Siemens Simatic S7-1500 Cpu Firmware - Improper Input Validation
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
CWE-20 Feb 08, 2016