CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2014-3623 EPSS 0.02
Apache Wss4j < 1.6.17 - Authentication Bypass
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
CWE-287 Oct 30, 2014
CVE-2014-8522 EPSS 0.01
Mcafee Network Data Loss Prevention < 9.2.2 - Authentication Bypass
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access.
CWE-287 Oct 29, 2014
CVE-2013-4594 EPSS 0.00
Payment for Webform <7.x-1.5 - Info Disclosure
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.
CWE-287 Oct 25, 2014
CVE-2014-8764 EPSS 0.01
DokuWiki <2014-05-05a - Auth Bypass
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.
CWE-287 Oct 22, 2014
CVE-2014-8763 EPSS 0.01
DokuWiki <2014-05-05b - Auth Bypass
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
CWE-287 Oct 22, 2014
CVE-2014-8088 EPSS 0.01
Zend Framework < 1.12.7 - Authentication Bypass
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.
CWE-287 Oct 22, 2014
CVE-2014-6387 EPSS 0.00
MantisBT <1.2.17 - Auth Bypass
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
CWE-287 Oct 22, 2014
CVE-2014-8329 EPSS 0.01
Schrack Technik Microcontrol Firmware < 1.7.0 - Authentication Bypass
Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.
CWE-287 Oct 20, 2014
CVE-2014-6116 EPSS 0.00
IBM Websphere MQ - Authentication Bypass
The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.
CWE-287 Oct 19, 2014
CVE-2014-4444 EPSS 0.00
Apple OS X <10.10 - Privilege Escalation
SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.
CWE-287 Oct 18, 2014
CVE-2014-4435 EPSS 0.00
Apple OS X <10.10 - Info Disclosure
The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN entry, which makes it easier for physically proximate attackers to obtain access via a brute-force attack involving a series of reboots.
CWE-287 Oct 18, 2014
CVE-2014-4425 EPSS 0.00
Apple OS X <10.10 - Info Disclosure
CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver begins" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.
CWE-287 Oct 18, 2014
CVE-2014-2066 EPSS 0.00
Jenkins <1.551-1.532.2 - Info Disclosure
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
CWE-287 Oct 17, 2014
CVE-2014-2062 EPSS 0.00
Jenkins <1.551-LTS <1.532.2 - Auth Bypass
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
CWE-287 Oct 17, 2014
CVE-2014-2927 1 PoC Analysis EPSS 0.07
F5 Arx - Authentication Bypass
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.
CWE-287 Oct 15, 2014
CVE-2014-6379 EPSS 0.01
Juniper Junos <11.4-R12,<12.1-R10,... - Privilege Escalation
Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R4, 13.2X50 before D20, 13.2X51 before D26 and D30, 13.2X52 before D15, 13.3 before R2, and 14.1 before R1, when a RADIUS accounting server is configured as [system accounting destination radius], creates an entry in /var/etc/pam_radius.conf, which might allow remote attackers to bypass authentication via unspecified vectors.
CWE-287 Oct 14, 2014
CVE-2014-3402 EPSS 0.00
Cisco Intrusion Prevention System < 7.0\(8\)e4 - Authentication Bypass
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.
CWE-287 Oct 10, 2014
CVE-2014-3393 EXPLOITED EPSS 0.01
Cisco Adaptive Security Appliance Software - Authentication Bypass
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.
CWE-287 Oct 10, 2014
CVE-2014-6632 EPSS 0.00
Joomla! <2.5.25-3.3.4 - Auth Bypass
Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authentication.
CWE-287 Oct 08, 2014
CVE-2014-5300 1 PoC Analysis EPSS 0.18
Adaptivecomputing Moab < 7.2.8 - Authentication Bypass
Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.
CWE-287 Oct 08, 2014