CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
4,085 results Clear all
CVE-2012-4078 EPSS 0.01
Cisco Unified Computing System - Authentication Bypass
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.
CWE-287 Sep 24, 2013
CVE-2013-5119 EPSS 0.00
Zimbra Collaboration Suite <6.0.16 - Info Disclosure
Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.
CWE-287 Sep 23, 2013
CVE-2013-1443 EPSS 0.01
Django < 1.4.8 - Authentication Bypass
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
CWE-287 Sep 23, 2013
CVE-2013-3473 EPSS 0.00
Cisco Prime Central For Hosted Collab... - Authentication Bypass
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.
CWE-287 Sep 20, 2013
CVE-2013-5497 EPSS 0.01
Cisco IPS - DoS
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.
CWE-287 Sep 19, 2013
CVE-2013-3613 1 PoC Analysis EPSS 0.08
Dahuasecurity Dvr0404hd-a - Authentication Bypass
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
CWE-287 Sep 17, 2013
CVE-2013-3039 EPSS 0.00
IBM Rational Requirements Composer <4.0.4 - Info Disclosure
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
CWE-287 Sep 12, 2013
CVE-2013-4061 EPSS 0.00
IBM Rational Policy Tester - Authentication Bypass
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.
CWE-287 Sep 09, 2013
CVE-2012-6603 EPSS 0.02
Paloaltonetworks Pan-os < 3.1.11 - Authentication Bypass
The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.
CWE-287 Aug 31, 2013
CVE-2013-3466 EPSS 0.01
Cisco Secure Access Control Server - Authentication Bypass
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
CWE-287 Aug 29, 2013
CVE-2013-3586 1 PoC Analysis EPSS 0.08
Samsung Smart Viewer - Authentication Bypass
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
CWE-287 Aug 28, 2013
CVE-2013-4958 EPSS 0.00
Puppet Enterprise <3.0.1 - Privilege Escalation
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
CWE-287 Aug 20, 2013
CVE-2013-2157 EPSS 0.00
Openstack Keystone < 2012.2.4 - Authentication Bypass
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
CWE-287 Aug 20, 2013
CVE-2013-3659 EPSS 0.00
Nttdocomo Overseas Usage - Authentication Bypass
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.
CWE-287 Aug 09, 2013
CVE-2013-2993 EPSS 0.00
IBM WebSphere Commerce <6.0.0.11 & <7.0.0.7 - Auth Bypass
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
CWE-287 Aug 01, 2013
CVE-2013-2056 EPSS 0.00
Redhat Satellite - Authentication Bypass
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
CWE-287 Jul 31, 2013
CVE-2013-2245 EPSS 0.00
Moodle - Authentication Bypass
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
CWE-287 Jul 29, 2013
CVE-2013-3431 1 PoC Analysis EPSS 0.04
Cisco Video Surveillance Manager < 6.3.3 - Authentication Bypass
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.
CWE-287 Jul 25, 2013
CVE-2013-3430 1 PoC Analysis EPSS 0.02
Cisco Video Surveillance Manager < 6.3.3 - Authentication Bypass
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.
CWE-287 Jul 25, 2013
CVE-2013-3656 EPSS 0.00
Cybozu Office < 9.1.0 - Authentication Bypass
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
CWE-287 Jul 20, 2013