CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-1106 EPSS 0.00
Akamai Client <3322 - CSRF
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
CWE-287 Jun 09, 2008
CVE-2008-2406 EPSS 0.01
SUN Java Asp Server < 4.0.2 - Authentication Bypass
The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.
CWE-287 Jun 04, 2008
CVE-2008-2524 EPSS 0.00
Blogphp - Authentication Bypass
BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie.
CWE-287 Jun 03, 2008
CVE-2008-2528 EPSS 0.01
Citrix Access Gateway < 4.5 - Authentication Bypass
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.
CWE-287 Jun 03, 2008
CVE-2008-2516 EPSS 0.00
Libpam-pgsql - Authentication Bypass
pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal when this function is executing, as demonstrated by a CTRL-C sequence at a sudo password prompt in an "auth sufficient pam_pgsql.so" configuration.
CWE-287 Jun 03, 2008
CVE-2008-0536 EPSS 0.03
Cisco Service Control Engine < 3.1.6 - Authentication Bypass
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.
CWE-287 May 22, 2008
CVE-2008-1949 EPSS 0.15
GnuTLS <2.2.4 - DoS
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.
CWE-287 May 21, 2008
CVE-2008-2347 1 PoC Analysis EPSS 0.02
Mypicgallery - Authentication Bypass
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.
CWE-287 May 20, 2008
CVE-2008-2282 1 PoC Analysis EPSS 0.04
Thomas Voecking Internet Photoshow - Authentication Bypass
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.
CWE-287 May 18, 2008
CVE-2008-2298 1 PoC Analysis EPSS 0.02
Sourceforge Web Slider - Authentication Bypass
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
CWE-287 May 18, 2008
CVE-2008-2269 1 PoC Analysis EPSS 0.02
Kevin Ludlow Austinsmoke Gastracker - Authentication Bypass
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.
CWE-287 May 16, 2008
CVE-2008-1930 EPSS 0.08
WordPress 2.5 - Auth Bypass
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
CWE-287 Apr 28, 2008
CVE-2008-1971 1 PoC Analysis EPSS 0.05
phShoutBox Final <1.5 - Privilege Escalation
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
CWE-287 Apr 27, 2008
CVE-2008-1938 EPSS 0.01
Sony Mylo COM-2 Japanese <1.002 - Info Disclosure
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.
CWE-287 Apr 25, 2008
CVE-2008-1897 EPSS 0.03
Asterisk Open Source <1.2.28-1.4.19.1 - DoS
The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.
CWE-287 Apr 23, 2008
CVE-2008-1904 1 PoC Analysis EPSS 0.04
Cicoandcico CcMail <1.0.1 - Auth Bypass
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.
CWE-287 Apr 22, 2008
CVE-2008-1883 EPSS 0.01
Blackboard Academic Suite 7.x - Info Disclosure
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.
CWE-287 Apr 18, 2008
CVE-2007-6714 EPSS 0.01
DBMail <2.2.9 - Auth Bypass
DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
CWE-287 Apr 17, 2008
CVE-2008-1868 1 PoC Analysis EPSS 0.05
Blog Pixel Motion - Info Disclosure
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.
CWE-287 Apr 17, 2008
CVE-2008-1727 1 PoC Analysis EPSS 0.04
KnowledgeQuest <2.7 - Auth Bypass
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
CWE-287 Apr 11, 2008