CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
4,085 results Clear all
CVE-2011-0435 EPSS 0.01
Gplhost Domain Technologie Control < 0.32.8 - Authentication Bypass
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.
CWE-287 Mar 07, 2011
CVE-2011-0279 EPSS 0.00
HP Multifunction Peripheral Digital S... - Authentication Bypass
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.
CWE-287 Mar 07, 2011
CVE-2011-0718 EPSS 0.01
Redhat Network Satellite Server - Authentication Bypass
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
CWE-287 Feb 25, 2011
CVE-2011-0392 EPSS 0.01
Cisco Telepresence Recording Server Software - Authentication Bypass
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.
CWE-287 Feb 25, 2011
CVE-2011-0384 EPSS 0.06
Cisco Telepresence Multipoint Switch Software - Authentication Bypass
The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.
CWE-287 Feb 25, 2011
CVE-2011-0383 EPSS 0.05
Cisco Telepresence Recording Server Software - Authentication Bypass
The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008.
CWE-287 Feb 25, 2011
CVE-2011-0380 EPSS 0.00
Cisco Telepresence Manager - Authentication Bypass
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.
CWE-287 Feb 25, 2011
CVE-2011-0453 EPSS 0.01
F-secure Internet Gatekeeper - Authentication Bypass
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.
CWE-287 Feb 18, 2011
CVE-2011-0091 EPSS 0.02
Microsoft Windows Server 2008 R2 & Windows 7 - Info Disclosure
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
CWE-287 Feb 10, 2011
CVE-2011-0039 EPSS 0.02
Microsoft Windows XP/Server 2003 - Privilege Escalation
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
CWE-287 Feb 09, 2011
CVE-2011-0920 1 PoC Analysis EPSS 0.04
IBM Lotus Domino - Authentication Bypass
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors, aka SPR PRAD89WGRS.
CWE-287 Feb 08, 2011
CVE-2011-0688 EPSS 0.03
Symantec Antivirus - Authentication Bypass
Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary commands via crafted messages over TCP, as discovered by Junaid Bohio, a different vulnerability than CVE-2010-0110 and CVE-2010-0111. NOTE: some of these details are obtained from third party information.
CWE-287 Jan 31, 2011
CVE-2011-0489 1 PoC Analysis EPSS 0.25
Objectivity/db - Authentication Bypass
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data, obtain sensitive information, or cause a denial of service by sending requests over TCP to (1) the Lock Server or (2) the Advanced Multithreaded Server, as demonstrated by commands that are ordinarily sent by the (a) ookillls and (b) oostopams applications. NOTE: some of these details are obtained from third party information.
CWE-287 Jan 18, 2011
CVE-2010-4690 EPSS 0.00
Cisco ASA 5500 <8.3.2 - Info Disclosure
The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which might allow remote attackers to obtain sensitive information via a HEAD request, aka Bug ID CSCte53635.
CWE-287 Jan 07, 2011
CVE-2010-4591 EPSS 0.00
IBM Lotus Mobile Connect < 6.1.3 - Authentication Bypass
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.
CWE-287 Dec 22, 2010
CVE-2010-4573 EPSS 0.02
Vmware Esxi - Authentication Bypass
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
CWE-287 Dec 22, 2010
CVE-2010-3905 EPSS 0.01
Eucalyptus - Authentication Bypass
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.
CWE-287 Dec 22, 2010
CVE-2010-4333 1 PoC Analysis EPSS 0.02
Pangramsoft Pointter Php Micro-bloggi... - Authentication Bypass
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.
CWE-287 Dec 22, 2010
CVE-2010-4332 1 PoC Analysis EPSS 0.03
Pangramsoft Pointter Php Content Mana... - Authentication Bypass
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.
CWE-287 Dec 22, 2010
CVE-2010-4481 EPSS 0.01
Phpmyadmin < 3.3.9.0 - Authentication Bypass
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
CWE-287 Dec 17, 2010