CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
67 results Clear all
CVE-2023-49340 9.8 CRITICAL 1 Writeup EPSS 0.00
Newland Nquire 1000 Interactive Kiosk <V1.00.011 - Privilege Escala...
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.
CWE-1390 Mar 09, 2024
CVE-2024-0822 7.5 HIGH EPSS 0.00
overt-engine - Auth Bypass
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.
CWE-1390 Jan 25, 2024
CVE-2023-4094 6.5 MEDIUM EPSS 0.00
ARCONTE Aurea 1.5.0.0 - DoS
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.
CWE-1390 Sep 19, 2023
CVE-2023-41900 3.5 LOW EPSS 0.00
Eclipse Jetty < 9.4.52 - Authentication Bypass
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already authenticated user, then the current request will still treat the user as authenticated. The authentication is then cleared from the session and subsequent requests will not be treated as authenticated. So a request on a previously authenticated session could be allowed to bypass authentication after it had been rejected by the `LoginService`. This impacts usages of the jetty-openid which have configured a nested `LoginService` and where that `LoginService` will is capable of rejecting previously authenticated users. Versions 9.4.52, 10.0.16, and 11.0.16 have a patch for this issue.
CWE-1390 Sep 15, 2023
CVE-2022-45860 5.3 MEDIUM EPSS 0.00
Fortinet Fortinac < 9.2.6 - Authentication Bypass
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
CWE-1390 May 03, 2023
CVE-2023-24890 6.5 MEDIUM EPSS 0.01
Microsoft OneDrive - Privilege Escalation
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
CWE-1390 Mar 14, 2023
CVE-2022-43400 9.8 CRITICAL EPSS 0.01
Siveillance Video Mobile Server <V2022 R2 - Info Disclosure
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow an unauthenticated remote attacker to access the application without a valid account.
CWE-1390 Oct 21, 2022