CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
4,085 results Clear all
CVE-2011-2701 EPSS 0.00
Freeradius - Authentication Bypass
The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.
CWE-287 Aug 04, 2011
CVE-2011-2361 EPSS 0.00
Google Chrome < 13.0.782.107 - Authentication Bypass
The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.
CWE-287 Aug 03, 2011
CVE-2011-2963 1 PoC Analysis EPSS 0.20
Progea Movicon - Authentication Bypass
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.
CWE-287 Jul 29, 2011
CVE-2011-2956 1 PoC Analysis EPSS 0.06
Azeotech Daqfactory < 5.84 - Authentication Bypass
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal.
CWE-287 Jul 28, 2011
CVE-2011-2758 EPSS 0.00
IBM Tivoli Directory Server - Authentication Bypass
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.
CWE-287 Jul 17, 2011
CVE-2011-2756 EPSS 0.00
Manageengine Servicedesk Plus - Authentication Bypass
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
CWE-287 Jul 17, 2011
CVE-2011-1409 EPSS 0.01
Frams' F*EX <20110610 - Auth Bypass
Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.
CWE-287 Jun 24, 2011
CVE-2009-5077 EPSS 0.00
Creloaded Cre Loaded < 6.2 - Authentication Bypass
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.
CWE-287 Jun 08, 2011
CVE-2009-5076 EXPLOITED EPSS 0.00
Creloaded Cre Loaded < 6.2 - Authentication Bypass
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009.
CWE-287 Jun 08, 2011
CVE-2011-1758 EPSS 0.00
SSSD <1.5.7 - Info Disclosure
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.
CWE-287 May 26, 2011
CVE-2011-1766 EPSS 0.00
MediaWiki <1.16.5 - Auth Bypass
includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.
CWE-287 May 23, 2011
CVE-2011-2155 EPSS 0.03
SmarterStats 6.0 - CSRF
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.
CWE-287 May 20, 2011
CVE-2011-1901 EPSS 0.01
Proofpoint Messaging Security Gateway - Authentication Bypass
The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to bypass authentication via unspecified vectors.
CWE-287 May 05, 2011
CVE-2011-1674 EPSS 0.01
NetGear ProSafe WNAP210 <2.0.12 - Auth Bypass
The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visiting recreate.php and then visiting index.php.
CWE-287 Apr 10, 2011
CVE-2011-1561 EPSS 0.00
IBM AIX 6.1 - Auth Bypass
The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.
CWE-287 Apr 05, 2011
CVE-2011-1472 EPSS 0.00
Nokia E75 <211.12.01 - Auth Bypass
The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.
CWE-287 Mar 29, 2011
CVE-2011-1520 EPSS 0.00
IBM Lotus Domino - Info Disclosure
The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.
CWE-287 Mar 25, 2011
CVE-2011-1519 1 PoC Analysis EPSS 0.09
IBM Lotus Domino <8.x - Auth Bypass
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
CWE-287 Mar 25, 2011
CVE-2011-1025 EPSS 0.07
Openldap - Authentication Bypass
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
CWE-287 Mar 20, 2011
CVE-2011-0438 EPSS 0.00
Arthurdejong Nss-pam-ldapd - Authentication Bypass
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
CWE-287 Mar 15, 2011