CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
110,638 results Clear all
CVE-2015-8669 5.3 MEDIUM EPSS 0.00
Phpmyadmin - Information Disclosure
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CWE-200 Dec 26, 2015
CVE-2015-6409 5.9 MEDIUM EPSS 0.00
Cisco Jabber - Information Disclosure
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
CWE-200 Dec 26, 2015
CVE-2015-7929 4.3 MEDIUM EPSS 0.02
eWON <10.1s0 - Info Disclosure
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CWE-200 Dec 23, 2015
CVE-2015-7927 6.1 MEDIUM EPSS 0.01
eWON <10.1s0 - XSS
Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 23, 2015
CVE-2015-6851 6.7 MEDIUM EPSS 0.00
RSA Securid Web Agent < 7.2.1 - Improper Access Control
EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.
CWE-284 Dec 23, 2015
CVE-2015-6471 5.3 MEDIUM EPSS 0.00
Eaton Proview - Information Disclosure
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.
CWE-200 Dec 23, 2015
CVE-2015-6431 6.5 MEDIUM EPSS 0.00
Cisco Ios XE - Resource Management Error
Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.
CWE-399 Dec 23, 2015
CVE-2015-8373 6.8 MEDIUM EPSS 0.03
ISC Kea <1.0.0-beta - DoS
The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) via a malformed packet.
CWE-20 Dec 22, 2015
CVE-2015-5001 4.3 MEDIUM EPSS 0.01
IBM Websphere Portal - Resource Management Error
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.
CWE-399 Dec 21, 2015
CVE-2015-4998 6.1 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
CWE-79 Dec 21, 2015
CVE-2015-4993 6.1 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.
CWE-79 Dec 21, 2015
CVE-2015-3195 5.3 MEDIUM 1 PoC Analysis EPSS 0.03
OpenSSL <1.0.2e - Info Disclosure
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
CWE-200 Dec 06, 2015
CVE-2015-4902 5.3 MEDIUM KEV EPSS 0.08
Oracle Jdk - Improper Access Control
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
CWE-284 Oct 22, 2015
CVE-2015-3238 6.5 MEDIUM EPSS 0.04
Linux-PAM <1.2.1 - DoS/Info Disclosure
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
CWE-200 Aug 24, 2015
CVE-2015-1769 6.6 MEDIUM KEV 1 PoC Analysis EPSS 0.32
Microsoft Windows 10 - Access Control
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."
CWE-264 Aug 15, 2015
CVE-2015-2890 6.0 MEDIUM EPSS 0.00
Dell Latitude/OptiPlex/Precision - Local Privilege Escalation
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Aug 01, 2015
CVE-2015-5521 4.8 MEDIUM EPSS 0.00
BlackCat CMS 1.1.2 - XSS
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.
CWE-79 Jul 14, 2015
CVE-2015-1793 6.5 MEDIUM 2 PoCs Analysis EPSS 0.83
Oracle Supply Chain Products Suite < 2.0.0.6 - Security Feature Bypass
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
CWE-254 Jul 09, 2015
CVE-2015-0071 6.5 MEDIUM KEV EPSS 0.37
Microsoft Internet Explorer <11 - Auth Bypass
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
Feb 11, 2015
CVE-2014-9271 5.4 MEDIUM EPSS 0.01
MantisBT <1.2.18 - XSS
Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.
CWE-79 Jan 09, 2015