CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
4,085 results Clear all
CVE-2009-3966 1 PoC Analysis EPSS 0.01
Arcade Trade Script 1.0 - Auth Bypass
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.
CWE-287 Nov 18, 2009
CVE-2009-3923 EPSS 0.01
VirtualBox <2.0.8-2.0.10 - Info Disclosure
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
CWE-287 Nov 10, 2009
CVE-2009-3862 EPSS 0.01
Novell eDirectory <8.7.3.10-8.8.5 - DoS
The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.
CWE-287 Nov 04, 2009
CVE-2009-3635 EPSS 0.01
Typo3 < 4.0.12 - Authentication Bypass
The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.
CWE-287 Nov 02, 2009
CVE-2009-3623 EPSS 0.01
Linux Kernel < 2.6.31.1 - Authentication Bypass
The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.
CWE-287 Oct 30, 2009
CVE-2009-3828 1 PoC Analysis EPSS 0.04
Everfocus Edr1600 - Authentication Bypass
The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.
CWE-287 Oct 30, 2009
CVE-2009-3657 EPSS 0.00
TIM Nelson Shared Sign-on - Authentication Bypass
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Oct 09, 2009
CVE-2009-3481 EPSS 0.00
Isygen Com Icrmbasic - Authentication Bypass
A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Sep 30, 2009
CVE-2009-3441 EPSS 0.00
Alienvault Ossim < 2.1 - Authentication Bypass
Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.
CWE-287 Sep 28, 2009
CVE-2009-2863 EPSS 0.00
Cisco Ios - Authentication Bypass
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
CWE-287 Sep 28, 2009
CVE-2009-3423 1 PoC Analysis EPSS 0.02
Zenas Paolink - Authentication Bypass
login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
CWE-287 Sep 25, 2009
CVE-2009-3422 1 PoC Analysis EPSS 0.02
Zenas Paoliber - Authentication Bypass
login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
CWE-287 Sep 25, 2009
CVE-2009-3421 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
Zenas Pao-bacheca Guestbook - Authentication Bypass
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
CWE-287 Sep 25, 2009
CVE-2009-3261 EPSS 0.01
Livestreet - Authentication Bypass
update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.
CWE-287 Sep 18, 2009
CVE-2009-3232 EPSS 0.01
Canonical Ubuntu Linux - Authentication Bypass
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
CWE-287 Sep 17, 2009
CVE-2009-3231 EPSS 0.05
Postgresql < 8.2.14 - Authentication Bypass
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
CWE-287 Sep 17, 2009
CVE-2009-3158 1 PoC Analysis EPSS 0.04
Carsten Wulff Simplephpweb - Authentication Bypass
admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.
CWE-287 Sep 10, 2009
CVE-2009-3107 EPSS 0.01
Symantec Altiris Deployment Solution - Authentication Bypass
Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
CWE-287 Sep 08, 2009
CVE-2008-7179 1 PoC Analysis EPSS 0.01
OTManager CMS 2.4 - Auth Bypass
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.
CWE-287 Sep 08, 2009
CVE-2009-2697 EPSS 0.00
Red Hat GDM <2.16.0-56 - Auth Bypass
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
CWE-287 Sep 04, 2009