CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-2913 5.9 MEDIUM 1 PoC Analysis EPSS 0.01
OrientDB Server Community Edition <2.0.15 and 2.1.x <2.1.1 - Info D...
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
CWE-200 Dec 31, 2015
CVE-2015-2896 5.3 MEDIUM EPSS 0.00
Idera Uptime Infrastructure Monitor <7.6 - Info Disclosure
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.
CWE-200 Dec 31, 2015
CVE-2015-2894 5.3 MEDIUM EPSS 0.01
Idera Uptime Infrastructure Monitor <7.2 - DoS
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
CWE-134 Dec 31, 2015
CVE-2015-8703 6.5 MEDIUM 1 PoC Analysis EPSS 0.04
ZTE Zxhn H108n R1a Firmware - Information Disclosure
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.
CWE-200 Dec 30, 2015
CVE-2015-7794 5.8 MEDIUM EPSS 0.01
Corega CG-WLNCM4G - DoS
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.
CWE-20 Dec 30, 2015
CVE-2015-7793 5.8 MEDIUM EPSS 0.01
Corega CG-WLBARAGM - SSRF
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.
CWE-17 Dec 30, 2015
CVE-2015-7790 6.1 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - XSS
Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2015
CVE-2015-7789 4.3 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - DoS
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.
CWE-20 Dec 30, 2015
CVE-2015-7787 4.3 MEDIUM EPSS 0.00
ASUS Japan WL-330NUL <3.0.0.42 - Info Disclosure
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase via unspecified vectors.
CWE-200 Dec 30, 2015
CVE-2015-7784 4.3 MEDIUM EPSS 0.00
BOKUBLOCK <1.1, <2.1 - SQL Injection
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CWE-89 Dec 30, 2015
CVE-2015-7782 6.1 MEDIUM EPSS 0.00
Let's PHP! Frame <2015-09-22 - XSS
Cross-site scripting (XSS) vulnerability in Let's PHP! Frame high-speed chat before 2015-09-22 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2015
CVE-2015-7252 6.1 MEDIUM 1 PoC Analysis EPSS 0.24
ZTE Zxhn H108n R1a Firmware - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.
CWE-79 Dec 30, 2015
CVE-2015-7249 4.9 MEDIUM 1 PoC Analysis EPSS 0.11
ZTE Zxhn H108n R1a Firmware - Access Control
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
CWE-264 Dec 30, 2015
CVE-2015-7791 6.3 MEDIUM EPSS 0.00
Collne Welcart <1.5.3 - SQL Injection
Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch parameter.
CWE-89 Dec 29, 2015
CVE-2015-5299 5.3 MEDIUM EPSS 0.08
Samba <4.1.22-4.3.3 - Info Disclosure
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
CWE-200 Dec 29, 2015
CVE-2015-5296 5.4 MEDIUM EPSS 0.03
Samba <4.1.22-4.3.3 - Info Disclosure
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
CWE-20 Dec 29, 2015
CVE-2015-3223 5.3 MEDIUM EPSS 0.19
Samba <4.1.22-4.3.3 - DoS
The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
CWE-399 Dec 29, 2015
CVE-2015-7786 6.1 MEDIUM EPSS 0.00
NTT DATA Smart Sourcing <2013-07-09 - XSS
Cross-site scripting (XSS) vulnerability in the NTT DATA Smart Sourcing JavaScript module 2003-11-26 through 2013-07-09 for Web Analytics Service allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 29, 2015
CVE-2015-6852 4.3 MEDIUM EPSS 0.00
EMC Secure Remote Services - Information Disclosure
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter.
CWE-200 Dec 28, 2015
CVE-2015-8660 6.7 MEDIUM 7 PoCs Analysis EPSS 0.63
Overlayfs Privilege Escalation
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
CWE-264 Dec 28, 2015