CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2014-0074 EPSS 0.00
Apache Shiro <1.2.3 - Auth Bypass
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
CWE-287 Oct 06, 2014
CVE-2013-3092 EPSS 0.01
Belkin N300 F7D7301v1 - Auth Bypass
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.
CWE-287 Sep 29, 2014
CVE-2014-3106 EPSS 0.00
IBM Rational Clearcase - Authentication Bypass
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protection mechanism, which allows remote attackers to bypass authentication and read files via the Help Server Administration feature.
CWE-287 Sep 23, 2014
CVE-2014-3101 EPSS 0.00
IBM Rational Clearcase - Authentication Bypass
The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a delay after a failed authentication attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-287 Sep 23, 2014
CVE-2014-5412 1 Writeup EPSS 0.01
Aveva Clearscada - Authentication Bypass
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.
CWE-287 Sep 18, 2014
CVE-2014-2685 EPSS 0.01
Zend Framework < 1.12.3 - Authentication Bypass
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CWE-287 Sep 04, 2014
CVE-2014-4619 EPSS 0.02
EMC RSA IMG <6.5.1P11-6.8.1P07 - Auth Bypass
EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username.
CWE-287 Aug 28, 2014
CVE-2014-0482 EPSS 0.01
Django <1.4.14-1.7 - Auth Bypass
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.
CWE-287 Aug 26, 2014
CVE-2014-4325 EPSS 0.00
Qualcomm LK - Privilege Escalation
The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to bypass intended device-lock and kernel-signature restrictions by using fastboot mode in a boot command for an arbitrary kernel image.
CWE-287 Aug 25, 2014
CVE-2014-0973 EPSS 0.00
Little Kernel Bootloader - Authentication Bypass
The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not check whether a certain digest size is consistent with the RSA_public_decrypt API specification, which makes it easier for attackers to bypass boot-image authentication requirements via trailing data.
CWE-287 Aug 25, 2014
CVE-2014-5385 EPSS 0.00
Shopizer < 1.1.5 - Authentication Bypass
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwords via a brute force attack.
CWE-287 Aug 21, 2014
CVE-2014-5175 EPSS 0.01
SAP Solution Manager - Authentication Bypass
The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a verb tampering attack and SAP_JTECHS.
CWE-287 Jul 31, 2014
CVE-2014-3895 EPSS 0.00
I-O DATA - Auth Bypass
The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow remote attackers to bypass authentication, and consequently obtain sensitive credential and configuration data, via unspecified vectors.
CWE-287 Jul 29, 2014
CVE-2014-3552 EPSS 0.00
Moodle < 2.3.11 - Authentication Bypass
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.
CWE-287 Jul 29, 2014
CVE-2014-4725 EXPLOITED 4 PoCs Analysis EPSS 0.82
MailPoet Newsletters <2.6.7 - Auth Bypass
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
CWE-287 Jul 27, 2014
CVE-2014-2955 EPSS 0.01
Raritan PX < 1.5.8 - Authentication Bypass
Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
CWE-287 Jul 14, 2014
CVE-2013-6117 EXPLOITED 3 PoCs Analysis EPSS 0.90
Dahuasecurity Dvr Firmware - Authentication Bypass
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
CWE-287 Jul 11, 2014
CVE-2014-3312 EPSS 0.00
Cisco Spa 301 1 Line IP Phone - Authentication Bypass
The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.
CWE-287 Jul 09, 2014
CVE-2014-2614 EPSS 0.01
HP SiteScope <11.13 - Auth Bypass
Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-2140.
CWE-287 Jul 07, 2014
CVE-2014-4168 1 Writeup EPSS 0.01
iodine <0.7.0 - Auth Bypass
(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.
CWE-287 Jul 03, 2014