CVE & Exploit Intelligence Database

Updated 29m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
4,085 results Clear all
CVE-2015-2033 EPSS 0.03
Infoblox Netmri < 6.8.2.11 - Authentication Bypass
Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges via a crafted terminal/anyterm-module request.
CWE-287 Feb 20, 2015
CVE-2014-9045 EPSS 0.01
ownCloud Server <5.0.18, <6.0.6 - Auth Bypass
The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password.
CWE-287 Feb 04, 2015
CVE-2014-9043 EPSS 0.00
ownCloud <5.0.18, <6.0.6, <7.0.3 - Auth Bypass
The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which triggers an unauthenticated bind.
CWE-287 Feb 04, 2015
CVE-2014-8033 EPSS 0.00
Cisco Webex Meetings Server - Authentication Bypass
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.
CWE-287 Jan 09, 2015
CVE-2014-9578 EPSS 0.00
VDG Security SENSE <2.3.13 - Auth Bypass
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
CWE-287 Jan 08, 2015
CVE-2013-4793 EPSS 0.00
Umbraco CMS <6.0.4 - RCE
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
CWE-287 Dec 27, 2014
CVE-2014-8896 EPSS 0.00
IBM InfoSphere Master Data Mgmt - Privilege Escalation
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors.
CWE-287 Dec 22, 2014
CVE-2014-8006 EPSS 0.00
Cisco Isb8320-e High-definition Ip-only Dvr - Authentication Bypass
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.
CWE-287 Dec 17, 2014
CVE-2014-7879 EPSS 0.00
Hp-ux - Authentication Bypass
HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors.
CWE-287 Dec 10, 2014
CVE-2014-7807 EPSS 0.00
Apache Cloudstack - Authentication Bypass
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
CWE-287 Dec 10, 2014
CVE-2014-9217 EPSS 0.01
Graylog2 <0.92 - Auth Bypass
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
CWE-287 Dec 08, 2014
CVE-2014-4631 EPSS 0.01
RSA Adaptive Auth 6.0.2.1-7.1 P3 - Privilege Escalation
RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.
CWE-287 Dec 08, 2014
CVE-2014-9278 EPSS 0.00
OpenSSH - Privilege Escalation
The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.
CWE-287 Dec 06, 2014
CVE-2014-9184 EPSS 0.07
ZTE ZXDSL 831CII - Auth Bypass
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.
CWE-287 Dec 02, 2014
CVE-2014-8424 1 PoC Analysis EPSS 0.54
Arris Vap2500 Firmware < 08.41 - Authentication Bypass
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
CWE-287 Nov 28, 2014
CVE-2014-4831 EPSS 0.00
IBM Security QRadar SIEM & QRadar Risk Manager <7.1 MR2 Patch 9 & <...
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.
CWE-287 Nov 28, 2014
CVE-2014-6318 EPSS 0.32
Microsoft RDP - Auth Bypass
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized login attempts supplying valid credentials, which makes it easier for remote attackers to bypass intended access restrictions via a series of attempts, aka "Remote Desktop Protocol (RDP) Failure to Audit Vulnerability."
CWE-287 Nov 11, 2014
CVE-2014-2373 EPSS 0.01
AXN-NET Ethernet module accessory 3.04 - Info Disclosure
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.
CWE-287 Nov 05, 2014
CVE-2014-8472 EPSS 0.00
CA Cloud Service Management < 2014 - Authentication Bypass
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
CWE-287 Nov 04, 2014
CVE-2014-6148 EPSS 0.00
IBM Tivoli Application Dependency Dis... - Authentication Bypass
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL.
CWE-287 Oct 31, 2014