CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
4,085 results Clear all
CVE-2012-5351 EPSS 0.00
Apache Axis2 - Auth Bypass
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
CWE-287 Oct 09, 2012
CVE-2012-4418 EPSS 0.00
Apache Axis2 < 1.7.9 - Authentication Bypass
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
CWE-287 Oct 09, 2012
CVE-2012-4457 EPSS 0.01
Openstack Keystone < 2012.1.2 - Authentication Bypass
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
CWE-287 Oct 09, 2012
CVE-2012-4456 EPSS 0.04
Openstack Keystone < 2012.1.2 - Authentication Bypass
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
CWE-287 Oct 09, 2012
CVE-2012-5309 EPSS 0.01
IBM Lotus Notes Traveler <8.5.3.3 - Auth Bypass
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-287 Oct 08, 2012
CVE-2012-3520 EPSS 0.00
Linux Kernel < 3.2.29 - Authentication Bypass
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
CWE-287 Oct 03, 2012
CVE-2012-1602 EPSS 0.00
Nextbbs - Authentication Bypass
user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.
CWE-287 Oct 01, 2012
CVE-2012-3492 EPSS 0.01
Condor - Authentication Bypass
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
CWE-287 Sep 28, 2012
CVE-2012-2287 EPSS 0.00
EMC Rsa Authentication Agent - Authentication Bypass
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.
CWE-287 Sep 25, 2012
CVE-2012-3137 3 PoCs Analysis EPSS 0.55
Oracle Database Server - Info Disclosure
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
CWE-287 Sep 21, 2012
CVE-2012-3741 EPSS 0.00
Apple Iphone OS < 5.1.1 - Authentication Bypass
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that performs purchase transactions.
CWE-287 Sep 20, 2012
CVE-2012-3721 EPSS 0.00
Apple Mac OS X < 10.7.4 - Authentication Bypass
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.
CWE-287 Sep 20, 2012
CVE-2012-5003 EPSS 0.01
No Machine NX Web Companion <3 - RCE
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.
CWE-287 Sep 19, 2012
CVE-2012-4926 1 PoC Analysis EPSS 0.05
Img Pals Photo Host 1.0 - RCE
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
CWE-287 Sep 15, 2012
CVE-2012-2983 1 PoC Analysis EPSS 0.51
Webmin <1.590 - Info Disclosure
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
CWE-287 Sep 11, 2012
CVE-2012-4392 EPSS 0.00
Owncloud Server - Authentication Bypass
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.
CWE-287 Sep 05, 2012
CVE-2012-4741 EPSS 0.00
PacketFence <3.3.0 - Auth Bypass
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.
CWE-287 Aug 31, 2012
CVE-2012-2285 EPSS 0.01
EMC Cloud Tiering Appliance Virtual Edition - Authentication Bypass
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted file during the authentication phase.
CWE-287 Aug 29, 2012
CVE-2012-3467 EPSS 0.01
Apache Qpid < 0.16 - Authentication Bypass
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
CWE-287 Aug 27, 2012
CVE-2012-3416 EPSS 0.02
Condor < 7.8.1 - Authentication Bypass
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
CWE-287 Aug 25, 2012