CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
110,638 results Clear all
CVE-2015-4943 5.3 MEDIUM EPSS 0.01
IBM Websphere MQ Light - Denial of Service
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4942.
CWE-17 Jan 01, 2016
CVE-2015-4941 5.3 MEDIUM EPSS 0.01
IBM Websphere MQ Light - Denial of Service
IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vectors.
CWE-17 Jan 01, 2016
CVE-2015-7441 6.8 MEDIUM EPSS 0.00
IBM WebSphere Process Server <8.5.6 - Info Disclosure
Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
CWE-17 Jan 01, 2016
CVE-2015-7447 5.3 MEDIUM EPSS 0.00
IBM WebSphere Portal - Auth Bypass
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF09 allows remote attackers to bypass intended Portal AccessControl REST API access restrictions and obtain sensitive information via unspecified vectors.
CWE-200 Dec 31, 2015
CVE-2015-7282 5.8 MEDIUM EPSS 0.00
Readynet Solutions Wrt300n-dd Firmware - Improper Input Validation
ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
CWE-20 Dec 31, 2015
CVE-2015-7279 5.3 MEDIUM EPSS 0.01
Amped Wireless R10000 <2.5.2.11 - Info Disclosure
Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
Dec 31, 2015
CVE-2015-6017 6.1 MEDIUM EPSS 0.01
ZyXEL P-660HW-T1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
CWE-79 Dec 31, 2015
CVE-2015-5994 6.8 MEDIUM EPSS 0.00
Mediabridge Medialink MWN-WAPR300N - Info Disclosure
The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the medialink account, which allows remote attackers to obtain administrative privileges by leveraging a Wi-Fi session.
CWE-255 Dec 31, 2015
CVE-2015-2918 6.1 MEDIUM EPSS 0.01
OrientDB Server Community Edition <2.0.15 & <2.1.1 - XSS
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
CWE-20 Dec 31, 2015
CVE-2015-2913 5.9 MEDIUM 1 PoC Analysis EPSS 0.01
OrientDB Server Community Edition <2.0.15 and 2.1.x <2.1.1 - Info D...
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
CWE-200 Dec 31, 2015
CVE-2015-2896 5.3 MEDIUM EPSS 0.00
Idera Uptime Infrastructure Monitor <7.6 - Info Disclosure
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.
CWE-200 Dec 31, 2015
CVE-2015-2894 5.3 MEDIUM EPSS 0.01
Idera Uptime Infrastructure Monitor <7.2 - DoS
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
CWE-134 Dec 31, 2015
CVE-2015-8703 6.5 MEDIUM 1 PoC Analysis EPSS 0.04
ZTE Zxhn H108n R1a Firmware - Information Disclosure
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.
CWE-200 Dec 30, 2015
CVE-2015-7794 5.8 MEDIUM EPSS 0.01
Corega CG-WLNCM4G - DoS
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.
CWE-20 Dec 30, 2015
CVE-2015-7793 5.8 MEDIUM EPSS 0.01
Corega CG-WLBARAGM - SSRF
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.
CWE-17 Dec 30, 2015
CVE-2015-7790 6.1 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - XSS
Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2015
CVE-2015-7789 4.3 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - DoS
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.
CWE-20 Dec 30, 2015
CVE-2015-7787 4.3 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - Info Disclosure
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase via unspecified vectors.
CWE-200 Dec 30, 2015
CVE-2015-7784 4.3 MEDIUM EPSS 0.00
BOKUBLOCK <1.1, <2.1 - SQL Injection
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Dec 30, 2015
CVE-2015-7782 6.1 MEDIUM EPSS 0.00
Let's PHP! Frame <2015-09-22 - XSS
Cross-site scripting (XSS) vulnerability in Let's PHP! Frame high-speed chat before 2015-09-22 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2015