CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
128 results Clear all
CVE-2022-31248 5.3 MEDIUM EPSS 0.00
SUSE Manager Server <4.1.46-1, <4.2.37-1 - Info Disclosure
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.
CWE-204 Jun 22, 2022
CVE-2022-0564 5.3 MEDIUM EPSS 0.00
Qlik Sense Enterprise on Windows - Info Disclosure
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured. The affected URI is /internal_forms_authentication/ the response time of the form is longer if the supplied user does not exists and shorter if the user exists.
CWE-204 Feb 21, 2022
CVE-2021-20049 7.5 HIGH EPSS 0.00
Sonicwall Sma 100 Firmware < 10.0.0.0 - Information Disclosure
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
CWE-204 Dec 23, 2021
CVE-2021-34580 7.5 HIGH EPSS 0.00
Mbconnectline Mbconnect24 < 2.9.0 - Information Disclosure
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
CWE-204 Oct 27, 2021
CVE-2021-38476 6.5 MEDIUM EPSS 0.00
InHand Networks IR615 Router <2.3.0.r4870 - Info Disclosure
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts.
CWE-204 Oct 19, 2021
CVE-2021-39189 5.3 MEDIUM EPSS 0.00
Pimcore < 10.1.3 - Information Disclosure
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.
CWE-204 Sep 15, 2021
CVE-2020-11063 3.7 LOW 1 Writeup EPSS 0.00
TYPO3 CMS <10.4.1 - Info Disclosure
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has been fixed in 10.4.2.
CWE-204 May 13, 2020
CVE-2016-9499 5.3 MEDIUM EPSS 0.01
Accellion FTP Server < fta_9_12_220 - Information Disclosure
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
CWE-204 Jul 13, 2018