CVE & Exploit Intelligence Database

Updated 59m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2013-4304 EPSS 0.00
Brion Vibber Centralauth Extension - Authentication Bypass
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.
CWE-287 Jan 26, 2014
CVE-2013-7137 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Burden <1.8.1 - Auth Bypass
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
CWE-287 Jan 26, 2014
CVE-2013-2192 EPSS 0.00
Apache Hadoop < 2.0.6-alpha - Authentication Bypass
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
CWE-287 Jan 24, 2014
CVE-2014-0674 EPSS 0.02
Cisco Video Surveillance Operations Manager - Authentication Bypass
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID CSCud10992.
CWE-287 Jan 24, 2014
CVE-2013-5429 EPSS 0.00
IBM Tivoli Federated Identity Manager <6.2.2 - Info Disclosure
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.
CWE-287 Jan 21, 2014
CVE-2013-6643 EPSS 0.00
Google Chrome < 32.0.1700.77 - Authentication Bypass
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.
CWE-287 Jan 16, 2014
CVE-2013-2820 EPSS 0.00
Sierra Wireless AirLink Raven X EV-DO - RCE
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
CWE-287 Jan 15, 2014
CVE-2013-7239 EPSS 0.00
memcached <1.4.17 - Auth Bypass
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.
CWE-287 Jan 13, 2014
CVE-2013-7292 EPSS 0.00
VASCO IDENTIKEY IAS 3.4.x - Auth Bypass
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.
CWE-287 Jan 13, 2014
CVE-2013-5009 EPSS 0.00
Symantec SEP <11.0.7.4-12.1.2 RU2 - Privilege Escalation
The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin account.
CWE-287 Jan 10, 2014
CVE-2013-7282 1 PoC Analysis EPSS 0.04
Nisuta NS-WIR150NE/NS-WIR300N - Auth Bypass
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header.
CWE-287 Jan 10, 2014
CVE-2013-5038 1 PoC Analysis EPSS 0.01
HOT HOTBOX <2.1.11 - Auth Bypass
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
CWE-287 Dec 30, 2013
CVE-2013-6006 EPSS 0.00
Cybozu Garoon - Authentication Bypass
Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.
CWE-287 Dec 28, 2013
CVE-2013-6979 EPSS 0.00
Cisco Ios XE - Authentication Bypass
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.
CWE-287 Dec 23, 2013
CVE-2013-6890 1 PoC Analysis EPSS 0.11
Debian Linux - Authentication Bypass
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
CWE-287 Dec 23, 2013
CVE-2013-6439 EPSS 0.00
Redhat Subscription Asset Manager - Authentication Bypass
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
CWE-287 Dec 23, 2013
CVE-2013-5413 EPSS 0.00
IBM Sterling B2B Integrator <5.2 - Auth Bypass
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
CWE-287 Dec 21, 2013
CVE-2013-5426 EPSS 0.00
IBM InfoSphere <10.1.5, 11.0 - Session Fixation
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.
CWE-287 Dec 19, 2013
CVE-2013-4001 EPSS 0.00
IBM Cognos Command Center < 10.1 - Authentication Bypass
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
CWE-287 Dec 14, 2013
CVE-2013-1364 EPSS 0.00
Zabbix < 1.8.15 - Authentication Bypass
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
CWE-287 Dec 14, 2013