CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
4,085 results Clear all
CVE-2008-6743 1 PoC Analysis EPSS 0.02
Shock-therapy Rsmscript - Authentication Bypass
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.
CWE-287 Apr 22, 2009
CVE-2008-6739 1 PoC Analysis EPSS 0.03
Toddwoolums Asp Download - Authentication Bypass
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
CWE-287 Apr 21, 2009
CVE-2008-6738 1 PoC Analysis EPSS 0.02
Mark Girling Myshoutpro - Authentication Bypass
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
CWE-287 Apr 21, 2009
CVE-2008-6723 1 PoC Analysis EPSS 0.02
Turnkeyforms Entertainment Portal - Authentication Bypass
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.
CWE-287 Apr 14, 2009
CVE-2008-6719 1 PoC Analysis EPSS 0.03
Uochm Justlistit - Authentication Bypass
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php.
CWE-287 Apr 13, 2009
CVE-2008-6718 1 PoC Analysis EPSS 0.03
Uochm Justbookit - Authentication Bypass
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php.
CWE-287 Apr 13, 2009
CVE-2008-6717 1 PoC Analysis EPSS 0.03
Uochm Signup - Authentication Bypass
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.
CWE-287 Apr 13, 2009
CVE-2008-6716 1 PoC Analysis EPSS 0.03
Preprojects Pre Ads Portal < 2.0 - Authentication Bypass
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.
CWE-287 Apr 13, 2009
CVE-2008-6714 1 PoC Analysis EPSS 0.02
Xecms - Authentication Bypass
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.
CWE-287 Apr 10, 2009
CVE-2008-6707 EPSS 0.00
Avaya Sip Enablement Services - Authentication Bypass
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."
CWE-287 Apr 10, 2009
CVE-2009-1155 EPSS 0.01
Cisco Adaptive Security Appliance 5500 - Authentication Bypass
Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.
CWE-287 Apr 09, 2009
CVE-2008-6667 1 PoC Analysis EPSS 0.01
Marc Melvin A+ Php Scripts News Manag... - Authentication Bypass
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
CWE-287 Apr 08, 2009
CVE-2008-6664 1 PoC Analysis EPSS 0.01
Yarck Sh-news - Authentication Bypass
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.
CWE-287 Apr 08, 2009
CVE-2008-6581 1 PoC Analysis EPSS 0.03
Phpaddedit - Authentication Bypass
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
CWE-287 Apr 02, 2009
CVE-2003-1570 EPSS 0.00
IBM Tivoli Storage Manager - Authentication Bypass
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
CWE-287 Mar 31, 2009
CVE-2008-6569 EPSS 0.01
Cybozu Garoon - Authentication Bypass
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
CWE-287 Mar 31, 2009
CVE-2009-0892 EPSS 0.00
IBM Websphere Application Server - Authentication Bypass
The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
CWE-287 Mar 31, 2009
CVE-2008-6553 1 PoC Analysis EPSS 0.04
Impliedbydesign Micro-cms < 0.3.5 - Authentication Bypass
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action.
CWE-287 Mar 30, 2009
CVE-2009-0591 EPSS 0.02
OpenSSL <0.9.8j - Info Disclosure
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.
CWE-287 Mar 27, 2009
CVE-2008-6523 1 PoC Analysis EPSS 0.02
Cale Dunlap Openinvoice - Authentication Bypass
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.
CWE-287 Mar 25, 2009