CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-3375 1 PoC Analysis EPSS 0.12
JamRoom <3.4.0 - Auth Bypass
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.
CWE-287 Jul 30, 2008
CVE-2008-3322 1 PoC Analysis EPSS 0.05
Maian Recipe <1.2 - Auth Bypass
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3321 1 PoC Analysis EPSS 0.09
Maian Uploader <4.0 - Auth Bypass
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3319 1 PoC Analysis EPSS 0.09
Maian Links <3.1 - Auth Bypass
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3320 1 PoC Analysis EPSS 0.04
Maian Guestbook <3.2 - Auth Bypass
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3317 1 PoC Analysis EPSS 0.10
Maian Search <1.1 - Auth Bypass
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3318 1 PoC Analysis EPSS 0.09
Maian Weblog <4.0 - Auth Bypass
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.
CWE-287 Jul 25, 2008
CVE-2008-3299 1 PoC Analysis EPSS 0.02
eSyndiCat 1.6 - Auth Bypass
eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Jul 25, 2008
CVE-2008-3292 1 PoC Analysis EPSS 0.02
EZWebAlbum 1.0 - Auth Bypass
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.
CWE-287 Jul 24, 2008
CVE-2008-3264 EPSS 0.07
Asterisk Open Source <1.2.30,1.4.21.2 - DoS
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (traffic amplification) via an IAX2 FWDOWNL request.
CWE-287 Jul 24, 2008
CVE-2008-3211 1 PoC Analysis EPSS 0.05
Scripteen Free Image Hosting Script <1.2.1 - Auth Bypass
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.
CWE-287 Jul 18, 2008
CVE-2008-3203 1 PoC Analysis EPSS 0.05
AuraCMS 2.2-2.2.2 - RCE
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
CWE-287 Jul 17, 2008
CVE-2008-2801 EPSS 0.04
Mozilla Firefox < 2.0.0.14 - Authentication Bypass
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
CWE-287 Jul 07, 2008
CVE-2008-3033 1 PoC Analysis EPSS 0.02
Rss Aggregator - Authentication Bypass
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.
CWE-287 Jul 07, 2008
CVE-2008-2920 1 PoC Analysis EPSS 0.06
Eztechhelp Ezcms < 1.2 - Authentication Bypass
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.
CWE-287 Jun 30, 2008
CVE-2008-2730 EPSS 0.01
Cisco Unified Communications Manager - Authentication Bypass
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.
CWE-287 Jun 26, 2008
CVE-2008-2879 EPSS 0.01
Benjacms Benja Cms - Authentication Bypass
Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.
CWE-287 Jun 26, 2008
CVE-2008-2833 1 PoC Analysis EPSS 0.04
Worldlevel Le.cms < 1.4 - Authentication Bypass
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.
CWE-287 Jun 24, 2008
CVE-2008-2705 EPSS 0.00
SUN Java System Access Manager - Authentication Bypass
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.
CWE-287 Jun 16, 2008
CVE-2008-0960 1 PoC Analysis EPSS 0.21
Juniper Session And Resource Control - Authentication Bypass
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
CWE-287 Jun 10, 2008