CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
4,085 results Clear all
CVE-2007-6398 1 PoC Analysis EPSS 0.03
Flat PHP Board <1.2 - Auth Bypass
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie.
CWE-287 Dec 17, 2007
CVE-2007-6384 EPSS 0.01
BEA WebLogic Mobility Server <3.6 - Info Disclosure
Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource access via unspecified vectors.
CWE-287 Dec 15, 2007
CVE-2007-6385 EPSS 0.00
Kerio WinRoute Firewall <6.4.1 - Info Disclosure
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
CWE-287 Dec 15, 2007
CVE-2007-6226 EPSS 0.00
APC AP7932 - Auth Bypass
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.
CWE-287 Dec 04, 2007
CVE-2007-6237 1 PoC Analysis EPSS 0.02
DeluxeBB 1.09 - Auth Bypass
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
CWE-287 Dec 04, 2007
CVE-2007-6234 1 PoC Analysis EPSS 0.05
FTP Admin 0.1.0 - Auth Bypass
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
CWE-287 Dec 04, 2007
CVE-2007-6145 EPSS 0.01
Hitachi JP1/File Transmission Server/FTP - Auth Bypass
Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vectors.
CWE-287 Nov 27, 2007
CVE-2007-6130 EPSS 0.00
gnump3d 2.9final - Auth Bypass
gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.
CWE-287 Nov 26, 2007
CVE-2007-6011 EPSS 0.01
BugHotel Reservation System <4.9.9 - Auth Bypass
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-287 Nov 16, 2007
CVE-2007-6006 EPSS 0.00
TestLink <1.7.1 - Info Disclosure
TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
CWE-287 Nov 15, 2007
CVE-2007-4693 EPSS 0.00
Mac OS X 10.4-10.4.10 - Privilege Escalation
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields."
CWE-287 Nov 15, 2007
CVE-2007-4680 EPSS 0.01
CFNetwork <10.4.11 - Info Disclosure
CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
CWE-287 Nov 15, 2007
CVE-2007-4692 EPSS 0.01
Apple Safari <3.0.4 - Auth Bypass
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.
CWE-287 Nov 15, 2007
CVE-2007-5988 EPSS 0.01
BtiTracker 1.4.4 - RCE
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.
CWE-287 Nov 15, 2007
CVE-2007-5987 EPSS 0.00
BtiTracker <1.4.5 - Auth Bypass
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.
CWE-287 Nov 15, 2007
CVE-2007-5770 EPSS 0.08
Ruby - Authentication Bypass
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.
CWE-287 Nov 14, 2007
CVE-2007-5913 1 PoC Analysis EPSS 0.17
JBC Explorer <7.20 RC1 - RCE
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.
CWE-287 Nov 10, 2007
CVE-2007-5797 EPSS 0.01
Apache Geronimo <2.2 - Auth Bypass
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
CWE-287 Nov 03, 2007
CVE-2007-5791 EPSS 0.04
Vonage Motorola Phone Adapter Vt2142-vd - Authentication Bypass
The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with malicious content.
CWE-287 Nov 01, 2007
CVE-2007-5752 2 PoCs Analysis EPSS 0.03
Agtc Websolutions Php-agtc Membership System - Authentication Bypass
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.
CWE-287 Oct 31, 2007