CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-7085 6.6 MEDIUM EPSS 0.01
Apple Quicktime < 7.7.8 - Memory Corruption
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
CWE-119 Jan 09, 2016
CVE-2015-6933 6.3 MEDIUM EPSS 0.02
Vmware Player - Improper Access Control
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.
CWE-284 Jan 09, 2016
CVE-2016-1565 6.1 MEDIUM EPSS 0.00
Drupal 7.x-1.x - XSS
Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.
CWE-79 Jan 08, 2016
CVE-2016-1501 4.3 MEDIUM EPSS 0.00
ownCloud Server <8.0.9 & <8.1.4 - Info Disclosure
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
CWE-200 Jan 08, 2016
CVE-2016-1498 6.1 MEDIUM EPSS 0.00
ownCloud Server <7.0.12-8.2.2 - XSS
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
CWE-79 Jan 08, 2016
CVE-2015-8766 6.1 MEDIUM EPSS 0.00
Symphony < 2.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.
CWE-79 Jan 08, 2016
CVE-2015-8376 6.1 MEDIUM EPSS 0.00
Symphony CMS 2.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
CWE-79 Jan 08, 2016
CVE-2014-7151 6.1 MEDIUM EPSS 0.00
NEX-Forms Lite 2.1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (1) do_edit or (2) do_insert action to wp-admin/admin-ajax.php.
CWE-79 Jan 08, 2016
CVE-2014-6444 6.1 MEDIUM EPSS 0.00
Titan Framework <1.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to iframe-googlefont-preview.php or the (2) text parameter to iframe-font-preview.php.
CWE-79 Jan 08, 2016
CVE-2015-8760 6.1 MEDIUM EPSS 0.00
Typo3 < 6.2.16 - Improper Input Validation
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."
CWE-20 Jan 08, 2016
CVE-2015-8759 5.4 MEDIUM EPSS 0.00
Typo3 < 6.2.16 - XSS
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.
CWE-79 Jan 08, 2016
CVE-2015-8758 5.4 MEDIUM EPSS 0.00
Typo3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Jan 08, 2016
CVE-2015-8757 6.1 MEDIUM EPSS 0.00
Typo3 - XSS
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.
CWE-79 Jan 08, 2016
CVE-2015-8756 5.4 MEDIUM EPSS 0.00
Typo3 < 6.2.16 - XSS
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 08, 2016
CVE-2015-8755 5.4 MEDIUM EPSS 0.00
Typo3 < 6.2.16 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Jan 08, 2016
CVE-2015-8615 5.0 MEDIUM EPSS 0.00
Xen 4.6 - DoS
The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large number of changes to the callback method (HVM_PARAM_CALLBACK_IRQ).
CWE-254 Jan 08, 2016
CVE-2015-8303 4.0 MEDIUM EPSS 0.00
Huawei DSM <V100R002C05SPC661 - Info Disclosure
Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file.
CWE-200 Jan 08, 2016
CVE-2015-8226 5.5 MEDIUM EPSS 0.00
Huawei ALE/TGEM - DoS
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8225.
CWE-20 Jan 08, 2016
CVE-2015-8225 5.5 MEDIUM EPSS 0.00
Huawei ALE/TGEM - DoS
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8226.
CWE-20 Jan 08, 2016
CVE-2015-7328 4.7 MEDIUM EPSS 0.00
Puppet Enterprise - Information Disclosure
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.
CWE-200 Jan 08, 2016