CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2014-4668 EPSS 0.01
Cherokee <1.2.103 - Auth Bypass
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.
CWE-287 Jul 02, 2014
CVE-2014-2005 6.8 MEDIUM EPSS 0.00
Sophos Disk Encryption <5.2.2 - Privilege Escalation
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
CWE-287 Jun 25, 2014
CVE-2014-3053 EPSS 0.01
IBM Security Access Manager For Web 8... - Authentication Bypass
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
CWE-287 Jun 21, 2014
CVE-2014-2609 EPSS 0.25
HP Executive Scorecard <9.42 - RCE
The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.
CWE-287 Jun 19, 2014
CVE-2014-3295 EPSS 0.01
Cisco Nx-os < 6.2\(2a\) - Authentication Bypass
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
CWE-287 Jun 14, 2014
CVE-2014-3781 EPSS 0.00
Dotclear < 2.6.2 - Authentication Bypass
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.
CWE-287 Jun 11, 2014
CVE-2014-3945 EPSS 0.00
TYPO3 <6.2 - Auth Bypass
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.
CWE-287 Jun 03, 2014
CVE-2014-3944 EPSS 0.00
TYPO3 6.2.0-6.2.3 - Auth Bypass
The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.
CWE-287 Jun 03, 2014
CVE-2013-0191 EPSS 0.01
Lucas Clemente Vella Libpam-pgsql - Authentication Bypass
libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.
CWE-287 Jun 03, 2014
CVE-2013-6470 EPSS 0.00
Redhat Openstack - Authentication Bypass
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.
CWE-287 Jun 02, 2014
CVE-2014-3780 EPSS 0.00
Citrix Vdi-in-a-box - Authentication Bypass
Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.
CWE-287 May 30, 2014
CVE-2013-6788 EPSS 0.00
Bitrix E-store Module < 14.0.0 - Authentication Bypass
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.
CWE-287 May 30, 2014
CVE-2014-3277 EPSS 0.00
Cisco Unified Communications Domain Manager - Authentication Bypass
The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005.
CWE-287 May 29, 2014
CVE-2013-4178 EPSS 0.00
Google Authenticator Login GA Login - Authentication Bypass
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
CWE-287 May 29, 2014
CVE-2013-2193 EPSS 0.00
Apache Hbase - Authentication Bypass
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
CWE-287 May 29, 2014
CVE-2012-6452 EPSS 0.00
Axway Email Firewall < 6.5.0 - Authentication Bypass
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
CWE-287 May 27, 2014
CVE-2014-0214 EPSS 0.00
Moodle <2.3.11-2.6.3 - Info Disclosure
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
CWE-287 May 27, 2014
CVE-2013-3977 1 PoC Analysis EPSS 0.29
IBM Sametime - Authentication Bypass
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
CWE-287 May 26, 2014
CVE-2013-3046 EPSS 0.00
IBM Sametime <8.5.2.1 & 9.0.0.1 - Info Disclosure
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.
CWE-287 May 26, 2014
CVE-2013-2756 EPSS 0.03
Apache CloudStack <4.0.2 & Citrix CloudPlatform <3.0.6 - Auth Bypass
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.
CWE-287 May 23, 2014