CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-8711 5.5 MEDIUM EPSS 0.00
Wireshark - Improper Input Validation
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.
CWE-20 Jan 04, 2016
CVE-2015-3182 5.5 MEDIUM EPSS 0.00
Wireshark <1.10.15 - DoS
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CWE-20 Jan 04, 2016
CVE-2015-8508 4.7 MEDIUM EPSS 0.00
Bugzilla <4.2.16-5.0.2 - XSS
Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot configuration is used, allows remote attackers to inject arbitrary web script or HTML via a crafted bug summary.
CWE-79 Jan 03, 2016
CVE-2015-5051 4.3 MEDIUM EPSS 0.00
IBM Maximo Asset Management - Access Control
IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow remote authenticated users to bypass intended access restrictions on query results via unspecified vectors.
CWE-264 Jan 03, 2016
CVE-2015-5037 5.4 MEDIUM EPSS 0.00
IBM Connections < 3.0.1.1 - CSRF
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CWE-352 Jan 03, 2016
CVE-2015-5036 5.4 MEDIUM EPSS 0.00
IBM Connections < 3.0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5035.
CWE-79 Jan 03, 2016
CVE-2015-5035 5.4 MEDIUM EPSS 0.00
IBM Connections < 3.0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5036.
CWE-79 Jan 03, 2016
CVE-2015-5023 5.4 MEDIUM EPSS 0.00
IBM Curam Social Program Management - SQL Injection
SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Jan 03, 2016
CVE-2015-5017 5.4 MEDIUM EPSS 0.00
IBM Change And Configuration Manageme... - Improper Access Control
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended access restrictions and establish a login session by entering an expired password.
CWE-284 Jan 03, 2016
CVE-2015-2007 5.0 MEDIUM EPSS 0.00
IBM Qradar Security Information And Event Manager - Path Traversal
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files via a crafted URL.
CWE-22 Jan 03, 2016
CVE-2015-1985 5.6 MEDIUM EPSS 0.00
IBM MQ Appliance M2000 < 8.0.0.3 - Improper Access Control
The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.
CWE-284 Jan 03, 2016
CVE-2015-1971 4.3 MEDIUM EPSS 0.00
IBM Rational Quality Manager - Denial of Service
Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Requirements Composer (RRC) 2.x and 3.x before 3.0.1.6 IF7 and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0; and Rational Software Architect Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote attackers to cause a denial of service via unknown vectors.
Jan 03, 2016
CVE-2015-7452 4.3 MEDIUM EPSS 0.00
IBM Maximo Asset Management <7.5.0.9 FP9, <7.6.0.3 FP3 - Info Discl...
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
CWE-200 Jan 02, 2016
CVE-2015-7438 4.7 MEDIUM EPSS 0.00
IBM Sterling B2B Integrator 5.2 - Info Disclosure
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
CWE-200 Jan 02, 2016
CVE-2015-7437 5.5 MEDIUM EPSS 0.00
IBM Sterling B2B Integrator 5.2 - Info Disclosure
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
CWE-200 Jan 02, 2016
CVE-2015-7431 6.1 MEDIUM EPSS 0.00
IBM Sterling B2B Integrator 5.2 - XSS
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jan 02, 2016
CVE-2015-7422 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
IBM i Access 7.1 - DoS
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.
CWE-119 Jan 02, 2016
CVE-2015-7416 4.0 MEDIUM EPSS 0.00
IBM i Access 7.1 - DoS
AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.
CWE-20 Jan 02, 2016
CVE-2015-7403 4.0 MEDIUM EPSS 0.00
IBM Spectrum Scale <4.1.1.3 & GPFS <4.1.0.8 - DoS
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.
Jan 02, 2016
CVE-2015-7396 5.4 MEDIUM EPSS 0.00
IBM Maximo Asset Management - Access Control
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.
CWE-264 Jan 02, 2016