CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
4,085 results Clear all
CVE-2008-1154 EPSS 0.06
Cisco Unified Communications - RCE
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
CWE-287 Apr 04, 2008
CVE-2008-0555 EPSS 0.01
Apache-ssl - Authentication Bypass
The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
CWE-287 Apr 04, 2008
CVE-2008-0706 EPSS 0.00
Compaq Presario A900 - Authentication Bypass
Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.
CWE-287 Mar 31, 2008
CVE-2008-0926 2 PoCs Analysis EPSS 0.66
Novell Edirectory < 8.7.3.10 - Authentication Bypass
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
CWE-287 Mar 28, 2008
CVE-2008-1238 EPSS 0.05
Mozilla Firefox <2.0.0.13 & SeaMonkey <1.1.9 - CSRF
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.
CWE-287 Mar 27, 2008
CVE-2008-1528 EPSS 0.00
ZyXEL Prestige - Info Disclosure
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.
CWE-287 Mar 26, 2008
CVE-2008-1469 EPSS 0.01
Gallarific Free Edition 1.1 - CSRF
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, different vectors than CVE-2008-1327. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Mar 24, 2008
CVE-2008-1395 EPSS 0.00
Plone CMS - Info Disclosure
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
CWE-287 Mar 20, 2008
CVE-2008-1356 EPSS 0.00
Sun Solaris 10 JDS - Auth Bypass
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.
CWE-287 Mar 17, 2008
CVE-2008-1334 EPSS 0.00
BT Home Hub - Auth Bypass
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde). NOTE: the '/' (slash) vector is already covered by CVE-2007-5383.
CWE-287 Mar 13, 2008
CVE-2008-1321 1 PoC Analysis EPSS 0.17
ASG-Sentry Network Manager <7.0.0 - DoS
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.
CWE-287 Mar 13, 2008
CVE-2008-1327 1 PoC Analysis EPSS 0.05
Gallarific - CSRF
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Mar 13, 2008
CVE-2008-1268 EPSS 0.01
Linksys WRT54G 7 - Auth Bypass
The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password.
CWE-287 Mar 10, 2008
CVE-2008-1259 EPSS 0.00
Zyxel P-2602HW-D1A - Auth Bypass
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
CWE-287 Mar 10, 2008
CVE-2008-1269 EPSS 0.00
Alice Gate 2 Plus Wi-Fi - Auth Bypass
cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request.
CWE-287 Mar 10, 2008
CVE-2008-1262 1 PoC Analysis EPSS 0.33
Airspan WiMax ProST 4.1-6.5.38.0 - Auth Bypass
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.
CWE-287 Mar 10, 2008
CVE-2008-1244 EXPLOITED 1 PoC Analysis EPSS 0.07
Belkin F5D7230-4 <9.01.10 - Auth Bypass
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.
CWE-287 Mar 10, 2008
CVE-2008-1264 EPSS 0.00
Linksys WRT54G - Info Disclosure
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.
CWE-287 Mar 10, 2008
CVE-2008-1134 1 PoC Analysis EPSS 0.02
OMEGA INSEL 7 - Auth Bypass
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.
CWE-287 Mar 04, 2008
CVE-2008-1130 EPSS 0.00
IBM WebSphere MQ <6.0.2.2, 5.3 - Auth Bypass
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
CWE-287 Mar 04, 2008