CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-4427 3 PoCs Analysis EPSS 0.06
Phlatline Personal Information Manager < 1.0 - Authentication Bypass
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.
CWE-287 Oct 03, 2008
CVE-2008-4319 1 PoC Analysis EPSS 0.03
Libra File Manager Php Filemanager < 1.18 - Authentication Bypass
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
CWE-287 Sep 29, 2008
CVE-2008-4244 2 PoCs Analysis EPSS 0.02
Rianxosencabos Cms - Authentication Bypass
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.
CWE-287 Sep 25, 2008
CVE-2008-4146 1 PoC Analysis EPSS 0.04
Addalink < 1.0 - Authentication Bypass
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.
CWE-287 Sep 24, 2008
CVE-2008-4167 1 PoC Analysis EPSS 0.05
Ezphotogallery - Authentication Bypass
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.
CWE-287 Sep 22, 2008
CVE-2008-3611 EPSS 0.00
Apple Mac OS X 10.4.11 - Auth Bypass
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
CWE-287 Sep 16, 2008
CVE-2008-3610 EPSS 0.00
Apple Mac OS X 10.5-10.5.4 - Auth Bypass
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
CWE-287 Sep 16, 2008
CVE-2008-4081 1 PoC Analysis EPSS 0.02
Stash - Authentication Bypass
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.
CWE-287 Sep 15, 2008
CVE-2008-3905 EPSS 0.03
Ruby <1.8.6-p287, <1.8.7-p72, <1.9-r18423 - SSRF
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
CWE-287 Sep 04, 2008
CVE-2008-3891 EPSS 0.00
Google Apps - Auth Bypass
The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and recipient field.
CWE-287 Sep 03, 2008
CVE-2008-3738 9.1 CRITICAL EPSS 0.00
SpaceTag LacoodaST <2.1.3 - Info Disclosure
Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Aug 27, 2008
CVE-2008-3729 EPSS 0.01
MicroWorld Technologies MailScan <5.6.a - Auth Bypass
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.
CWE-287 Aug 20, 2008
CVE-2008-3703 EPSS 0.25
Symantec Veritas Storage Foundation <5.1 - RCE
The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.
CWE-287 Aug 18, 2008
CVE-2008-3579 EPSS 0.00
Calacode @Mail 5.41 - Info Disclosure
Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this can be leveraged for remote exploitation of CVE-2008-3395. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Aug 10, 2008
CVE-2008-3504 EPSS 0.00
mask PHP File Manager <2.3 - Info Disclosure
Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies."
CWE-287 Aug 06, 2008
CVE-2008-3503 EPSS 0.00
Plain Black WebGUI <7.5.13 - Info Disclosure
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
CWE-287 Aug 06, 2008
CVE-2008-3428 EPSS 0.00
phpFreeChat 1.1 - Session Fixation
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
CWE-287 Jul 31, 2008
CVE-2008-3425 EPSS 0.01
Sun Java System Web Server 7.0 - Privilege Escalation
Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors.
CWE-287 Jul 31, 2008
CVE-2008-3411 EPSS 0.01
Axesstel AXW-D800 - Info Disclosure
The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi, and (5) cgi-bin/route.cgi, which allows remote attackers to change the modem's configuration via direct requests.
CWE-287 Jul 31, 2008
CVE-2008-3407 1 PoC Analysis EPSS 0.03
phpLinkat 0.1 - Auth Bypass
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.
CWE-287 Jul 31, 2008