CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
4,085 results Clear all
CVE-2009-0906 EPSS 0.00
IBM Websphere Application Server - Authentication Bypass
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
CWE-287 Aug 13, 2009
CVE-2008-6965 1 PoC Analysis EPSS 0.02
AJ Square AJ Auction - Authentication Bypass
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.
CWE-287 Aug 13, 2009
CVE-2008-6951 EPSS 0.01
Cms.maury91 Maurycms - Authentication Bypass
MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.
CWE-287 Aug 12, 2009
CVE-2008-6947 1 PoC Analysis EPSS 0.03
Collabtive - Authentication Bypass
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php.
CWE-287 Aug 12, 2009
CVE-2008-6939 1 PoC Analysis EPSS 0.04
Turnkeyforms Web Hosting Directory - Authentication Bypass
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.
CWE-287 Aug 12, 2009
CVE-2008-6919 1 PoC Analysis EPSS 0.02
Taskdriver < 1.3 - Authentication Bypass
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
CWE-287 Aug 10, 2009
CVE-2009-0669 EPSS 0.01
ZODB <3.8.2 - Auth Bypass
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.
CWE-287 Aug 07, 2009
CVE-2008-6916 1 PoC Analysis EPSS 0.05
Siemens Speedstream 5200 - Authentication Bypass
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.
CWE-287 Aug 07, 2009
CVE-2008-6912 2 PoCs Analysis EPSS 0.03
Zeeways Shaadiclone - Authentication Bypass
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.
CWE-287 Aug 07, 2009
CVE-2009-2410 EPSS 0.00
SSSD 0.4.1 - Info Disclosure
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent attackers to obtain access by sending the account's username, in conjunction with an arbitrary password, over an ssh connection.
CWE-287 Jul 30, 2009
CVE-2009-2642 1 PoC Analysis EPSS 0.01
Desi Short URL Script 1.0 - Auth Bypass
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.
CWE-287 Jul 28, 2009
CVE-2009-2481 EPSS 0.00
Six Apart Movable Type <4.261 - Auth Bypass
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.
CWE-287 Jul 16, 2009
CVE-2008-6864 1 PoC Analysis EPSS 0.00
Xigla Absolute Live Support .net - Authentication Bypass
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6863 1 PoC Analysis EPSS 0.00
Xigla Absolute Form Processor.net - Authentication Bypass
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6862 1 PoC Analysis EPSS 0.00
Xigla Absolute Content Rotator - Authentication Bypass
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6861 1 PoC Analysis EPSS 0.00
Xigla Absolute Newsletter - Authentication Bypass
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6860 1 PoC Analysis EPSS 0.00
Xigla Absolute Poll Manager XE - Authentication Bypass
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6859 1 PoC Analysis EPSS 0.00
Xigla Absolute Control Panel XE - Authentication Bypass
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6858 1 PoC Analysis EPSS 0.00
Xigla Absolute Banner Manager.net - Authentication Bypass
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009
CVE-2008-6857 1 PoC Analysis EPSS 0.01
Xigla Absolute Podcast.net - Authentication Bypass
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
CWE-287 Jul 14, 2009