CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
4,085 results Clear all
CVE-2008-7156 1 PoC Analysis EPSS 0.01
EkinBoard <1.1.0 - Auth Bypass
EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.
CWE-287 Sep 02, 2009
CVE-2008-7124 2 PoCs Analysis EPSS 0.08
Zkup - Authentication Bypass
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.
CWE-287 Aug 31, 2009
CVE-2008-7086 1 PoC Analysis EPSS 0.02
Maianscriptworld Maian Greetings - Authentication Bypass
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.
CWE-287 Aug 26, 2009
CVE-2008-7081 EPSS 0.00
Raidsonic Icy Box Nas - Authentication Bypass
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Aug 25, 2009
CVE-2008-7051 1 PoC Analysis EPSS 0.02
Ajsquare AJ Article - Authentication Bypass
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.
CWE-287 Aug 24, 2009
CVE-2008-7047 1 PoC Analysis EPSS 0.01
Natterchat - Authentication Bypass
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.
CWE-287 Aug 24, 2009
CVE-2008-7046 1 PoC Analysis EPSS 0.01
Ajsquare Free Polling Script - Authentication Bypass
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Aug 24, 2009
CVE-2008-7045 1 PoC Analysis EPSS 0.02
Ajsquare Free Polling Script - Authentication Bypass
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.
CWE-287 Aug 24, 2009
CVE-2008-7041 1 PoC Analysis EPSS 0.01
Ajsquare AJ Classifieds - Authentication Bypass
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
CWE-287 Aug 24, 2009
CVE-2003-1574 EPSS 0.00
Tikiwiki Cms/groupware - Authentication Bypass
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.
CWE-287 Aug 24, 2009
CVE-2008-7028 1 PoC Analysis EPSS 0.02
Aves Rpg Board < 0.0.8 - Authentication Bypass
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.
CWE-287 Aug 21, 2009
CVE-2008-7027 1 PoC Analysis EPSS 0.01
Libra File Manager Php Filemanager < 1.18 - Authentication Bypass
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.
CWE-287 Aug 21, 2009
CVE-2008-7019 1 PoC Analysis EPSS 0.02
Esqlanelapse - Authentication Bypass
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.
CWE-287 Aug 21, 2009
CVE-2008-7008 1 PoC Analysis EPSS 0.07
Hyperstop Web Host Directory - Authentication Bypass
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.
CWE-287 Aug 19, 2009
CVE-2008-7007 1 PoC Analysis EPSS 0.02
Phpversion Php VX Guestbook - Authentication Bypass
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
CWE-287 Aug 19, 2009
CVE-2008-7006 1 PoC Analysis EPSS 0.04
Phpversion Php VX Guestbook - Authentication Bypass
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
CWE-287 Aug 19, 2009
CVE-2008-6984 EPSS 0.00
Parallels Plesk - Authentication Bypass
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.
CWE-287 Aug 19, 2009
CVE-2009-1878 EPSS 0.00
Adobe Coldfusion < 8.0.1 - Authentication Bypass
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Aug 18, 2009
CVE-2009-2088 EPSS 0.01
IBM WebSphere Application Server <7.0.0.5 - Auth Bypass
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.
CWE-287 Aug 13, 2009
CVE-2009-2085 EPSS 0.00
IBM WebSphere Application Server <6.1.0.25-7.0.0.5 - Auth Bypass
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
CWE-287 Aug 13, 2009