CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-4037 4 PoCs Analysis EPSS 0.76
Microsoft Windows <2008 - RCE
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
CWE-287 Nov 12, 2008
CVE-2008-5042 1 PoC Analysis EPSS 0.05
Zeeways Photovideotube < 1.1 - Authentication Bypass
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.
CWE-287 Nov 12, 2008
CVE-2008-5040 1 PoC Analysis EPSS 0.02
Graphiks Myforum - Authentication Bypass
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.
CWE-287 Nov 12, 2008
CVE-2008-4784 1 PoC Analysis EPSS 0.02
Aflog - Authentication Bypass
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.
CWE-287 Oct 29, 2008
CVE-2008-4783 1 PoC Analysis EPSS 0.02
Easy-script Tlads - Authentication Bypass
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."
CWE-287 Oct 29, 2008
CVE-2008-4752 1 PoC Analysis EPSS 0.02
Tech Logic Tlnews - Authentication Bypass
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.
CWE-287 Oct 27, 2008
CVE-2008-4722 EPSS 0.01
SUN Integrated Lights-out Manager < 2.0 - Authentication Bypass
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.
CWE-287 Oct 23, 2008
CVE-2008-3815 EPSS 0.00
Cisco ASA/PX <7.0.8.3-8.1.1.13 - Auth Bypass
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.
CWE-287 Oct 23, 2008
CVE-2008-4721 1 PoC Analysis EPSS 0.02
PHP Jabbers Post Comment - Information Disclosure
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
CWE-287 Oct 23, 2008
CVE-2008-4714 1 PoC Analysis EPSS 0.02
Atomic Photo Album - Authentication Bypass
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
CWE-287 Oct 23, 2008
CVE-2008-4708 1 PoC Analysis EPSS 0.02
Sylvain Pasquet Bbzl.php - Authentication Bypass
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.
CWE-287 Oct 23, 2008
CVE-2008-4689 EPSS 0.01
Mantis < 1.1.2 - Authentication Bypass
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
CWE-287 Oct 22, 2008
CVE-2008-4679 EPSS 0.00
IBM Websphere Application Server - Authentication Bypass
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.
CWE-287 Oct 22, 2008
CVE-2008-4649 1 PoC Analysis EPSS 0.01
Elxis Cms - Authentication Bypass
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
CWE-287 Oct 22, 2008
CVE-2008-4622 1 PoC Analysis EPSS 0.05
Phpfastnews - Authentication Bypass
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
CWE-287 Oct 21, 2008
CVE-2008-4614 1 PoC Analysis EPSS 0.08
Portalapp - Authentication Bypass
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.
CWE-287 Oct 20, 2008
CVE-2008-4576 EPSS 0.05
Linux Kernel < 2.6.25.17 - Authentication Bypass
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
CWE-287 Oct 15, 2008
CVE-2008-3466 1 PoC Analysis EPSS 0.85
Microsoft HIS <2006 - Auth Bypass
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
CWE-287 Oct 15, 2008
CVE-2008-4515 EPSS 0.00
Blue Coat Systems K9 Web Protection - Authentication Bypass
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling JavaScript.
CWE-287 Oct 09, 2008
CVE-2008-3814 EPSS 0.00
Cisco Unity <4.2.1-5.0.1-7.0.2 - Auth Bypass
Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.
CWE-287 Oct 08, 2008