CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
4,085 results Clear all
CVE-2010-4488 EPSS 0.01
Google Chrome < 8.0.552.214 - Authentication Bypass
Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
CWE-287 Dec 07, 2010
CVE-2010-4478 1 Writeup EPSS 0.00
Openbsd Openssh < 5.6 - Authentication Bypass
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
CWE-287 Dec 06, 2010
CVE-2010-4252 1 Writeup EPSS 0.02
Openssl < 1.0.0b - Authentication Bypass
OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.
CWE-287 Dec 06, 2010
CVE-2010-4279 3 PoCs Analysis EPSS 0.82
Artica Pandora Fms < 3.1 - Authentication Bypass
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.
CWE-287 Dec 02, 2010
CVE-2010-3868 EPSS 0.00
Redhat Certificate System - Authentication Bypass
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
CWE-287 Nov 17, 2010
CVE-2010-4232 1 PoC Analysis EPSS 0.05
Camtron Cmnc-200 Firmware - Authentication Bypass
The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI.
CWE-287 Nov 17, 2010
CVE-2010-1838 EPSS 0.00
Apple Mac OS X - Authentication Bypass
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
CWE-287 Nov 15, 2010
CVE-2010-3896 EPSS 0.01
IBM Omnifind - Authentication Bypass
The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.
CWE-287 Nov 12, 2010
CVE-2010-4211 EPSS 0.00
Ebay Paypal < 3.0 - Authentication Bypass
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
CWE-287 Nov 09, 2010
CVE-2010-3852 EPSS 0.01
Redhat Luci < 0.22.4 - Authentication Bypass
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
CWE-287 Nov 06, 2010
CVE-2010-4121 EPSS 0.01
IBM Tivoli Provisioning Manager OS Deployment - Authentication Bypass
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.
CWE-287 Oct 28, 2010
CVE-2008-7263 EPSS 0.01
pyftpdlib <0.5.0 - DoS
ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-287 Oct 19, 2010
CVE-2007-6737 EPSS 0.01
pyftpdlib <0.2.0 - Info Disclosure
FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-287 Oct 19, 2010
CVE-2010-3739 EPSS 0.00
IBM Db2 Universal Database < 9.5 - Authentication Bypass
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
CWE-287 Oct 05, 2010
CVE-2010-3686 EPSS 0.01
Drupal - Authentication Bypass
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CWE-287 Sep 29, 2010
CVE-2010-3685 EPSS 0.01
Drupal - Authentication Bypass
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CWE-287 Sep 29, 2010
CVE-2010-3091 EPSS 0.01
Drupal <6.18 & <5.x-1.4 - Auth Bypass
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CWE-287 Sep 29, 2010
CVE-2010-1820 EPSS 0.00
Apple Mac OS X - Authentication Bypass
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
CWE-287 Sep 21, 2010
CVE-2010-3471 EPSS 0.00
IBM FileNet P8 AE <4.0.2.7 - Info Disclosure
Session fixation vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.7-P8AE-FP007 allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Sep 20, 2010
CVE-2010-2731 2 PoCs Analysis EPSS 0.67
Microsoft IIS 5.1 - Auth Bypass
Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory Authentication Bypass Vulnerability."
CWE-287 Sep 15, 2010