CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2015-4998 6.1 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
CWE-79 Dec 21, 2015
CVE-2015-4993 6.1 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.
CWE-79 Dec 21, 2015
CVE-2015-3195 5.3 MEDIUM 1 PoC Analysis EPSS 0.03
OpenSSL <1.0.2e - Info Disclosure
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
CWE-200 Dec 06, 2015
CVE-2015-4902 5.3 MEDIUM KEV EPSS 0.08
Oracle Jdk - Improper Access Control
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
CWE-284 Oct 22, 2015
CVE-2015-3238 6.5 MEDIUM EPSS 0.04
Linux-PAM <1.2.1 - DoS/Info Disclosure
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
CWE-200 Aug 24, 2015
CVE-2015-1769 6.6 MEDIUM KEV 1 PoC Analysis EPSS 0.32
Microsoft Windows 10 - Access Control
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."
CWE-264 Aug 15, 2015
CVE-2015-2890 6.0 MEDIUM EPSS 0.00
Dell Latitude/OptiPlex/Precision - Local Privilege Escalation
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Aug 01, 2015
CVE-2015-5521 4.8 MEDIUM EPSS 0.00
BlackCat CMS 1.1.2 - XSS
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.
CWE-79 Jul 14, 2015
CVE-2015-1793 6.5 MEDIUM 2 PoCs Analysis EPSS 0.83
Oracle Supply Chain Products Suite < 2.0.0.6 - Security Feature Bypass
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
CWE-254 Jul 09, 2015
CVE-2015-0071 6.5 MEDIUM KEV EPSS 0.37
Microsoft Internet Explorer <11 - Auth Bypass
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
Feb 11, 2015
CVE-2014-9271 5.4 MEDIUM EPSS 0.01
MantisBT <1.2.18 - XSS
Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.
CWE-79 Jan 09, 2015
CVE-2010-5312 6.1 MEDIUM EPSS 0.05
jQuery UI <1.10.0 - XSS
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
CWE-79 Nov 24, 2014
CVE-2014-8559 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Denial of Service
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
CWE-400 Nov 10, 2014
CVE-2014-3690 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Denial of Service
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.
CWE-400 Nov 10, 2014
CVE-2014-3647 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Denial of Service
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Nov 10, 2014
CVE-2014-3646 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Denial of Service
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Nov 10, 2014
CVE-2014-3611 4.7 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Race Condition
Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.
CWE-362 Nov 10, 2014
CVE-2014-3610 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17.2 - Denial of Service
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.
Nov 10, 2014
CVE-2014-8086 4.7 MEDIUM EPSS 0.00
Linux Kernel < 3.17 - Race Condition
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
CWE-362 Oct 13, 2014
CVE-2014-7975 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.17 - Denial of Service
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Oct 13, 2014