CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
4,085 results Clear all
CVE-2010-1910 EPSS 0.01
Consona Dynamic Agent - Authentication Bypass
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.
CWE-287 May 12, 2010
CVE-2009-4843 EPSS 0.02
Toutvirtual Virtualiq - Authentication Bypass
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console.
CWE-287 May 07, 2010
CVE-2010-1613 EPSS 0.00
Moodle < 1.9.8 - Authentication Bypass
Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.
CWE-287 Apr 29, 2010
CVE-2010-1596 EPSS 0.00
Sitracker Support Incident Tracker < 3.50 - Authentication Bypass
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
CWE-287 Apr 28, 2010
CVE-2009-4830 EPSS 0.01
Openx - Authentication Bypass
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.
CWE-287 Apr 27, 2010
CVE-2009-4821 EPSS 0.00
Dlink Dir-615 - Authentication Bypass
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors.
CWE-287 Apr 27, 2010
CVE-2009-4808 2 PoCs Analysis EPSS 0.02
Graugon Php Article Publisher - Authentication Bypass
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.
CWE-287 Apr 23, 2010
CVE-2009-4806 1 PoC Analysis EPSS 0.02
Digitalinterchange Digital Interchang... - Authentication Bypass
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-287 Apr 23, 2010
CVE-2009-4801 1 PoC Analysis EPSS 0.02
Will Kraft Ez-blog - Authentication Bypass
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
CWE-287 Apr 23, 2010
CVE-2010-0744 EPSS 0.00
aMSN 0.98.3 - SSL Man-in-the-Middle
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.
CWE-287 Apr 20, 2010
CVE-2010-1222 EPSS 0.00
CA XOsoft r12.5 - Info Disclosure
CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.
CWE-287 Apr 07, 2010
CVE-2010-1221 EPSS 0.00
CA XOsoft <r12.5 - Info Disclosure
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
CWE-287 Apr 07, 2010
CVE-2009-2936 3 PoCs Analysis EPSS 0.68
Varnish - Authentication Bypass
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.
CWE-287 Apr 05, 2010
CVE-2010-1191 EPSS 0.00
Sahana disaster management system <0.6.2.2 - Auth Bypass
Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.
CWE-287 Mar 31, 2010
CVE-2010-0521 EPSS 0.00
Apple Mac OS X < 10.6.2 - Authentication Bypass
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
CWE-287 Mar 30, 2010
CVE-2010-0498 EPSS 0.00
Apple Mac OS X < 10.6.2 - Authentication Bypass
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
CWE-287 Mar 30, 2010
CVE-2010-1097 EPSS 0.00
DeDeCMS 5.5 GBK - Auth Bypass
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
CWE-287 Mar 24, 2010
CVE-2010-1040 EPSS 0.00
OpenPNE - Auth Bypass
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.
CWE-287 Mar 23, 2010
CVE-2010-1022 EPSS 0.00
TYPO3 <0.2.13 - Auth Bypass
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
CWE-287 Mar 19, 2010
CVE-2010-0447 EPSS 0.06
HP Openview Performance Insight < 5.4 - Authentication Bypass
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.
CWE-287 Mar 10, 2010