CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-5708 1 PoC Analysis EPSS 0.05
SlimCMS 1.0.0 - Open Redirect
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
CWE-287 Dec 24, 2008
CVE-2008-5692 1 PoC Analysis EPSS 0.01
Ipswitch WS_FTP Server Manager <6.1.1 - Auth Bypass
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
CWE-287 Dec 19, 2008
CVE-2008-5686 EPSS 0.01
IBM Tivoli Provisioning Manager <5.1.1.1 IF0006 - RCE
IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.
CWE-287 Dec 19, 2008
CVE-2008-5558 EPSS 0.02
Asterisk Business Edition - Authentication Bypass
Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname matching.
CWE-287 Dec 17, 2008
CVE-2008-4223 EPSS 0.02
Apple Mac OS X Server < 10.5.5 - Authentication Bypass
Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors.
CWE-287 Dec 17, 2008
CVE-2008-5576 1 PoC Analysis EPSS 0.02
sCssBoard <1.13 - Auth Bypass
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
CWE-287 Dec 15, 2008
CVE-2008-5575 EPSS 0.00
Pro Clan Manager <0.4.2 - Info Disclosure
Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CWE-287 Dec 15, 2008
CVE-2008-5497 1 PoC Analysis EPSS 0.04
BandSite CMS 1.1.4 - Auth Bypass
BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true.
CWE-287 Dec 12, 2008
CVE-2008-4032 EPSS 0.59
Microsoft Office Sharepoint Server - Authentication Bypass
Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
CWE-287 Dec 10, 2008
CVE-2008-5407 EPSS 0.01
Symantec Backup Exec - Auth Bypass
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors.
CWE-287 Dec 10, 2008
CVE-2008-5355 EPSS 0.18
Java Runtime Environment <6 - RCE
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
CWE-287 Dec 05, 2008
CVE-2008-5296 EPSS 0.00
Gallery <1.5.10, <1.6-RC3 - Auth Bypass
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.
CWE-287 Dec 01, 2008
CVE-2008-5221 1 PoC Analysis EPSS 0.05
wPortfolio <0.3 - Auth Bypass
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
CWE-287 Nov 25, 2008
CVE-2008-5219 1 PoC Analysis EPSS 0.04
VideoScript <4.0.1.50 - Auth Bypass
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.
CWE-287 Nov 25, 2008
CVE-2008-5158 EPSS 0.01
Client Software WinCom LPD Total <3.0.2.623 - Auth Bypass
Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vectors involving "simply skipping the auth stage."
CWE-287 Nov 18, 2008
CVE-2008-5125 1 PoC Analysis EPSS 0.02
Castillocentral Ccleague - Authentication Bypass
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.
CWE-287 Nov 18, 2008
CVE-2008-5124 EPSS 0.01
Jscape Secure FTP Applet < 4.8.0 - Authentication Bypass
JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
CWE-287 Nov 18, 2008
CVE-2006-5268 EPSS 0.18
Trend Micro Serverprotect - Authentication Bypass
Unspecified vulnerability in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via vectors related to obtaining "administrative access to the RPC interface."
CWE-287 Nov 17, 2008
CVE-2008-5065 1 PoC Analysis EPSS 0.02
Easy-script Tlguesbook - Authentication Bypass
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.
CWE-287 Nov 13, 2008
CVE-2008-5022 EPSS 0.13
Mozilla Firefox < 2.0.0.18 - Authentication Bypass
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.
CWE-287 Nov 13, 2008