CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
1,290 results Clear all
CVE-2024-28981 8.5 HIGH EPSS 0.00
Hitachi Vantara Pentaho Data Integration & Analytics <10.1.0.0, <9....
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
CWE-522 Sep 12, 2024
CVE-2024-20489 8.4 HIGH EPSS 0.00
Cisco IOS XR - Info Disclosure
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
CWE-522 Sep 11, 2024
CVE-2024-44815 4.6 MEDIUM 1 PoC Analysis EPSS 0.11
Hathway Skyworth Router CM5100 <4.1.1.24 - Info Disclosure
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
CWE-522 Sep 10, 2024
CVE-2024-40710 8.8 HIGH EPSS 0.09
Veeam Backup & Replication - RCE
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
CWE-522 Sep 07, 2024
CVE-2024-39278 4.2 MEDIUM EPSS 0.00
Echostar Fusion < 2.7.0.10 - Insufficiently Protected Credentials
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
CWE-522 Sep 05, 2024
CVE-2023-49233 8.8 HIGH EPSS 0.00
Visual Planning Admin Center <8 - Privilege Escalation
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain different types of configured credentials and potentially elevate their privileges to administrator level.
CWE-522 Sep 03, 2024
CVE-2024-40704 4.9 MEDIUM EPSS 0.00
IBM InfoSphere Information Server 11.7 - Info Disclosure
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
CWE-522 Aug 15, 2024
CVE-2024-31800 6.8 MEDIUM EPSS 0.00
GC2 Indoor Security Camera 1080P - Privilege Escalation
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.
CWE-522 Aug 15, 2024
CVE-2024-7813 5.3 MEDIUM 1 Writeup EPSS 0.00
Prison Management System - Insufficiently Protected Credentials
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently protected credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-522 Aug 15, 2024
CVE-2024-39818 7.5 HIGH EPSS 0.01
Zoom Rooms < 6.0.0 - Insufficiently Protected Credentials
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
CWE-522 Aug 14, 2024
CVE-2024-36460 8.1 HIGH EPSS 0.00
Zabbix - Plaintext Password Disclosure in Front-End Audit Log
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
CWE-522 Aug 12, 2024
CVE-2024-6118 9.1 CRITICAL EPSS 0.00
Hamastar MeetingHub Paperless Meetings 2021 - Info Disclosure
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
CWE-522 Aug 05, 2024
CVE-2024-7389 7.5 HIGH EPSS 0.03
Incsub Forminator < 1.29.2 - Insufficiently Protected Credentials
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.
CWE-522 Aug 02, 2024
CVE-2024-3082 4.2 MEDIUM EPSS 0.00
Proges Sensor Net Connect Firmware - Plaintext Password Storage
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.
CWE-522 Jul 31, 2024
CVE-2024-6492 7.4 HIGH EPSS 0.01
Drevolutions Remote Desktop Manager <2024.2.14.0 - Info Disclosure
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.
CWE-522 Jul 16, 2024
CVE-2024-39733 5.5 MEDIUM EPSS 0.00
IBM Datacap Navigator <9.1.10 - Info Disclosure
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.
CWE-522 Jul 14, 2024
CVE-2024-38453 7.5 HIGH EPSS 0.00
Avalara for Salesforce <7.0 - Info Disclosure
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
CWE-522 Jul 03, 2024
CVE-2023-41926 8.8 HIGH EPSS 0.00
Webserver <unknown> - Info Disclosure
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.
CWE-522 Jul 02, 2024
CVE-2024-39879 5.0 MEDIUM EPSS 0.00
Jetbrains Teamcity < 2024.03.3 - Insufficiently Protected Credentials
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
CWE-522 Jul 01, 2024
CVE-2024-39878 4.1 MEDIUM EPSS 0.00
Jetbrains Teamcity < 2024.03.3 - Insufficiently Protected Credentials
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
CWE-522 Jul 01, 2024