CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
4,085 results Clear all
CVE-2013-4877 EPSS 0.01
Verizon Wireless Network Extender - Info Disclosure
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
CWE-287 Jul 18, 2013
CVE-2013-4875 EPSS 0.00
Verizon Wireless Network Extender SCS-2U01 - Privilege Escalation
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a SysReq interrupt.
CWE-287 Jul 18, 2013
CVE-2013-4874 EPSS 0.01
Uboot - Privilege Escalation
The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a crafted HDMI cable and using a sys session to modify the ramboot environment variable.
CWE-287 Jul 18, 2013
CVE-2013-4784 1 PoC Analysis EPSS 0.51
HP iLO - Auth Bypass
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
CWE-287 Jul 08, 2013
CVE-2013-4783 EPSS 0.04
Dell iDRAC6 <1.92 and iDRAC7 <1.23.23 - Auth Bypass
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
CWE-287 Jul 08, 2013
CVE-2013-4782 1 PoC Analysis EPSS 0.64
Supermicro BMC - Auth Bypass
The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
CWE-287 Jul 08, 2013
CVE-2013-3581 EPSS 0.00
Choice Wireless Wixfmr-111 - Authentication Bypass
ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information via an Ajax (1) wmxState or (2) netState request.
CWE-287 Jul 02, 2013
CVE-2013-4731 EPSS 0.01
Choice Wireless Green Packet WIXFMR-111 - RCE
ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via shell metacharacters in the pip parameter in an Ajax tag_ipPing request, a different vulnerability than CVE-2013-3581.
CWE-287 Jun 30, 2013
CVE-2013-2310 EPSS 0.00
Softbank Wi-fi Spot Configuration Software - Authentication Bypass
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the WISPrClient application before 1.3.1, SoftBank Disney Mobile Android smartphones with the Wi-Fi application before 1.7.1, and WILLCOM Android smartphones with the Wi-Fi application before 1.7.1, does not properly connect to access points, which allows remote attackers to obtain sensitive information by leveraging access to an 802.11 network.
CWE-287 Jun 17, 2013
CVE-2013-1205 EPSS 0.00
Cisco WebEx Meetings Server - Info Disclosure
The Event Center module in Cisco WebEx Meetings Server does not perform request authentication in all intended circumstances, which allows remote attackers to discover host keys and event passwords via crafted URLs, aka Bug ID CSCue62485.
CWE-287 Jun 06, 2013
CVE-2013-0985 EPSS 0.00
Apple Mac OS X <10.8.4 - DoS
Disk Management in Apple Mac OS X before 10.8.4 does not properly authenticate attempts to disable FileVault, which allows local users to cause a denial of service (loss of encryption functionality) via an unspecified command line.
CWE-287 Jun 05, 2013
CVE-2013-2067 EPSS 0.10
Apache Tomcat < 6.0.37 - Authentication Bypass
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
CWE-287 Jun 01, 2013
CVE-2013-2313 EPSS 0.00
Lockon Ec-cube - Authentication Bypass
Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 May 29, 2013
CVE-2013-1211 EPSS 0.00
Cisco NX-OS - Privilege Escalation
Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM access via (1) spoofed STUN packets or (2) a crafted VMware ESXi instance, aka Bug ID CSCud14832.
CWE-287 May 29, 2013
CVE-2013-1209 EPSS 0.00
Cisco NX-OS - RCE
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM packets, which allows remote attackers to disable packet-level encryption and integrity protection via crafted packets, aka Bug ID CSCud14710.
CWE-287 May 29, 2013
CVE-2013-2954 EPSS 0.00
IBM InfoSphere Optim Data Growth - Auth Bypass
The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the number of incorrect authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-287 May 27, 2013
CVE-2013-2059 EPSS 0.01
Openstack Keystone < 8.0.0a0 - Authentication Bypass
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
CWE-287 May 21, 2013
CVE-2013-1200 EPSS 0.00
Cisco Secure ACS - Session Fixation
Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787.
CWE-287 May 16, 2013
CVE-2013-1188 EPSS 0.01
Cisco CUCM - DoS
Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515.
CWE-287 May 16, 2013
CVE-2013-1337 EPSS 0.23
Microsoft .net Framework - Authentication Bypass
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
CWE-287 May 15, 2013