CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
4,085 results Clear all
CVE-2007-5714 EPSS 0.01
Gentoo Mldonkey Ebuild < 2.9.0 - Authentication Bypass
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
CWE-287 Oct 30, 2007
CVE-2007-5578 EPSS 0.01
Secureideas Basic Analysis And Security Engine - Authentication Bypass
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and possibly other vectors.
CWE-287 Oct 18, 2007
CVE-2007-5391 EPSS 0.04
HP Select Identity - Authentication Bypass
Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.
CWE-287 Oct 12, 2007
CVE-2007-5383 EPSS 0.02
Alcatel Speedtouch 7G Router < 6.2.6.b - Authentication Bypass
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues.
CWE-287 Oct 12, 2007
CVE-2007-5374 1 PoC Analysis EPSS 0.05
Lightblog - Authentication Bypass
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
CWE-287 Oct 11, 2007
CVE-2007-5006 EPSS 0.02
Broadcom Brightstor Arcserve Backup L... - Authentication Bypass
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.
CWE-287 Oct 01, 2007
CVE-2007-5152 EPSS 0.02
SUN Java System Access Manager - Authentication Bypass
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
CWE-287 Oct 01, 2007
CVE-2007-5162 EPSS 0.01
Ruby - Authentication Bypass
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.
CWE-287 Oct 01, 2007
CVE-2007-3754 EPSS 0.01
Apple Iphone - Authentication Bypass
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.
CWE-287 Sep 27, 2007
CVE-2007-5113 1 PoC Analysis EPSS 0.05
ROI Revolution Urchin < 5.7.03 - Authentication Bypass
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.
CWE-287 Sep 26, 2007
CVE-2007-5085 EPSS 0.01
Apache Geronimo - Authentication Bypass
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
CWE-287 Sep 26, 2007
CVE-2007-5057 EPSS 0.02
Netsupport Manager Client - Authentication Bypass
NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager.
CWE-287 Sep 24, 2007
CVE-2007-5008 EPSS 0.01
Hp-ux - Authentication Bypass
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
CWE-287 Sep 20, 2007
CVE-2007-4747 EPSS 0.03
Cisco Video Surveillance IP Gateway E... - Authentication Bypass
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote attackers to perform administrative actions, aka CSCsj31729.
CWE-287 Sep 06, 2007
CVE-2007-4632 EPSS 0.00
Cisco IOS 12.2E/12.2F/12.2S - Auth Bypass
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.
CWE-287 Aug 31, 2007
CVE-2007-4548 EPSS 0.01
Apache Geronimo 2.0 - Auth Bypass
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
CWE-287 Aug 27, 2007
CVE-2007-4438 EPSS 0.01
Ampache <3.3.3.5 - Info Disclosure
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Aug 20, 2007
CVE-2007-4419 1 PoC Analysis EPSS 0.10
Olate Download (od) 3.4.1 - Info Disclosure
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.
CWE-287 Aug 18, 2007
CVE-2007-4364 EPSS 0.01
Fedora Commons <2.2.1 - Info Disclosure
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP server, and (2) a reauthentication attempt that throws an exception, which allows remote attackers to trigger use of a cached authentication decision. NOTE: authentication can be bypassed by using vector 1 followed by vector 2, and possibly can be bypassed by using a single vector.
CWE-287 Aug 15, 2007
CVE-2007-4203 EPSS 0.01
Mambo 4.6.2 - Info Disclosure
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
CWE-287 Aug 08, 2007