CVE & Exploit Intelligence Database

Updated 57m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
20 results Clear all
CVE-2020-7268 4.3 MEDIUM EPSS 0.00
Mcafee Email Gateway < 7.6.406 - Path Traversal
Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a restricted directory.
CWE-22 Sep 16, 2020
CVE-2016-8005 6.5 MEDIUM EPSS 0.00
Intel Security McAfee Email Gateway <7.6.404h1128596 - Info Disclosure
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a forged attached filename that uses a null byte within the filename extension.
CWE-264 Mar 14, 2017
CVE-2016-3969 6.1 MEDIUM EPSS 0.00
McAfee Email Gateway <7.6.404 - XSS
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.
CWE-79 Apr 06, 2016
CVE-2015-1619 EPSS 0.00
McAfee Email Gateway <7.6.3.2-7.0.5-5.6 - XSS
Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client user interface in McAfee Email Gateway (MEG) 7.6.x before 7.6.3.2, 7.5.x before 75.6, 7.0.x through 7.0.5, 5.6, and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified tokens in Digest messages.
CWE-79 Feb 17, 2015
CVE-2013-7104 EPSS 0.01
McAfee Email Gateway 7.6 - RCE
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.
CWE-78 Dec 14, 2013
CVE-2013-7103 EPSS 0.01
McAfee Email Gateway 7.6 - Command Injection
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.
CWE-78 Dec 14, 2013
CVE-2013-7092 EPSS 0.00
McAfee Email Gateway 7.6 - SQL Injection
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) event_id, (3) reason, (4) events_order, (5) emailstatus_order, or (6) emailstatus_col JSON keys.
CWE-89 Dec 13, 2013
CVE-2013-6349 EPSS 0.01
Mcafee Email Gateway - Code Injection
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
CWE-94 Nov 02, 2013
CVE-2012-4597 EPSS 0.00
McAfee EWS <5.6.3-7.0.1 - XSS
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard.
CWE-79 Aug 22, 2012
CVE-2012-4596 EPSS 0.00
McAfee Email Gateway <7.0.1 - Path Traversal
Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL.
CWE-22 Aug 22, 2012
CVE-2012-4595 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.2 - Auth Bypass
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors.
CWE-287 Aug 22, 2012
CVE-2012-4586 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.1 - Privilege Escalation
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
CWE-264 Aug 22, 2012
CVE-2012-4585 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.1 - Info Disclosure
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL.
CWE-264 Aug 22, 2012
CVE-2012-4584 EPSS 0.00
McAfee EWS <5.5-5.6 & MEG 7.0 - Info Disclosure
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not properly encrypt system-backup data, which makes it easier for remote authenticated users to obtain sensitive information by reading a backup file, as demonstrated by obtaining password hashes.
CWE-310 Aug 22, 2012
CVE-2012-4583 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.1 - Info Disclosure
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
CWE-200 Aug 22, 2012
CVE-2012-4582 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.1 - Auth Bypass
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to reset the passwords of arbitrary administrative accounts via unspecified vectors.
CWE-264 Aug 22, 2012
CVE-2012-4581 EPSS 0.00
McAfee EWS <5.5.6 & MEG 7.0 <1 - Auth Bypass
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a "Logout Failure" issue.
CWE-287 Aug 22, 2012
CVE-2012-4580 EPSS 0.00
McAfee EWS <5.5.6 & MEG <7.0.1 - XSS
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard.
CWE-79 Aug 22, 2012
CVE-2010-2116 EPSS 0.01
Mcafee Email Gateway - Incorrect Permission Assignment
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.
CWE-732 May 28, 2010
CVE-2009-1348 EPSS 0.00
Mcafee Active Virus Defense - Improper Input Validation
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.
CWE-20 Apr 30, 2009