CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2012-5158 EPSS 0.00
Puppet Enterprise <2.6.1 - Privilege Escalation
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
CWE-287 Mar 14, 2014
CVE-2013-6031 1 PoC Analysis EPSS 0.04
Huawei E355 Firmware - Authentication Bypass
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2) api/device/information, (3) api/wlan/basic-settings, (4) api/wlan/mac-filter, (5) api/monitoring/status, or (6) api/dhcp/settings.
CWE-287 Mar 11, 2014
CVE-2013-7322 EPSS 0.00
OATH Toolkit <2.4.1 - Info Disclosure
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.
CWE-287 Mar 09, 2014
CVE-2013-4966 EPSS 0.00
Puppet Enterprise <3.2.0 - Info Disclosure
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
CWE-287 Mar 09, 2014
CVE-2014-1911 EPSS 0.00
Foscam FI8910W <11.37.2.55 - Info Disclosure
The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and password.
CWE-287 Mar 06, 2014
CVE-2014-2075 EPSS 0.03
TIBCO Enterprise Administrator <1.0.0 - Command Injection
TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which allows remote attackers to execute arbitrary commands via unspecified vectors.
CWE-287 Feb 27, 2014
CVE-2014-0743 EPSS 0.00
Cisco Unified Communications Manager - Authentication Bypass
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.
CWE-287 Feb 27, 2014
CVE-2014-0739 EPSS 0.00
Cisco Adaptive Security Appliance Software - Authentication Bypass
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.
CWE-287 Feb 22, 2014
CVE-2014-0738 EPSS 0.00
Cisco Adaptive Security Appliance Software - Authentication Bypass
The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66770.
CWE-287 Feb 22, 2014
CVE-2014-0737 EPSS 0.00
Cisco Unified IP Phone 7960g - Authentication Bypass
The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795.
CWE-287 Feb 22, 2014
CVE-2014-0733 EPSS 0.00
Cisco Unified Communications Manager - Authentication Bypass
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.
CWE-287 Feb 20, 2014
CVE-2014-0732 EPSS 0.00
Cisco Unified Communications Manager - Authentication Bypass
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.
CWE-287 Feb 20, 2014
CVE-2012-1100 EPSS 0.00
Red Hat JBoss Operations Network (JON) <3.0.1-2.4.2 - Auth Bypass
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
CWE-287 Feb 14, 2014
CVE-2012-0062 EPSS 0.00
Redhat Jboss Operations Network < 2.4.1 - Authentication Bypass
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
CWE-287 Feb 14, 2014
CVE-2014-0725 EPSS 0.00
Cisco Unified Communications Manager - Authentication Bypass
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.
CWE-287 Feb 13, 2014
CVE-2014-0722 EPSS 0.01
Cisco Unified Communications Manager - Authentication Bypass
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCum05347.
CWE-287 Feb 13, 2014
CVE-2011-4091 EPSS 0.01
libnet6 <1.3.14 - Info Disclosure
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.
CWE-287 Feb 10, 2014
CVE-2013-7183 1 PoC Analysis EPSS 0.10
Seowon Intech SWC-9100 - DoS
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_default action.
CWE-287 Feb 04, 2014
CVE-2013-6035 EPSS 0.04
Gatehouse - Authentication Bypass
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.
CWE-287 Feb 04, 2014
CVE-2014-0015 EPSS 0.02
cURL/libcurl <7.35 - Auth Bypass
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
CWE-287 Feb 02, 2014