CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-4703 5.3 MEDIUM EPSS 0.01
Rename - Path Traversal
Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname parameter.
CWE-22 Jan 12, 2016
CVE-2015-4671 6.1 MEDIUM 1 Writeup EPSS 0.00
Opencart < 2.1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
CWE-79 Jan 12, 2016
CVE-2015-8335 6.5 MEDIUM EPSS 0.00
Huawei VCN500 <V100R002C00SPC201 - Info Disclosure
Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.
CWE-200 Jan 11, 2016
CVE-2015-7706 6.1 MEDIUM EPSS 0.00
Secure Data Space SDS-API <3.5.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.
CWE-79 Jan 11, 2016
CVE-2015-7399 5.3 MEDIUM EPSS 0.00
IBM Integration Bus - Information Disclosure
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.
CWE-200 Jan 11, 2016
CVE-2015-7024 6.7 MEDIUM EPSS 0.00
Apple OS X <10.11.1 - Privilege Escalation
Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an unexpected directory by an application that has a valid Apple digital signature.
Jan 11, 2016
CVE-2015-7116 4.3 MEDIUM EPSS 0.01
Apple Tvos < 9.0 - Memory Corruption
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.
CWE-119 Jan 10, 2016
CVE-2015-7115 4.3 MEDIUM EPSS 0.01
Apple Iphone OS < 9.1 - Memory Corruption
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.
CWE-119 Jan 10, 2016
CVE-2015-8512 4.6 MEDIUM EPSS 0.00
Mozilla Firefox OS <2.5 - Info Disclosure
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
CWE-284 Jan 09, 2016
CVE-2015-8511 6.4 MEDIUM EPSS 0.00
Mozilla Firefox OS <2.5 - Info Disclosure
Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
CWE-362 Jan 09, 2016
CVE-2015-8510 6.1 MEDIUM EPSS 0.00
Mozilla Firefox OS <2.5 - XSS
Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.
CWE-79 Jan 09, 2016
CVE-2015-7575 5.9 MEDIUM EPSS 0.02
Mozilla NSS <3.20.2 - Info Disclosure
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
CWE-19 Jan 09, 2016
CVE-2015-7117 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7092.
CWE-119 Jan 09, 2016
CVE-2015-7092 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7091 6.6 MEDIUM EPSS 0.05
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7090 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7089 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7088 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7087 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-7086 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016