CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
1,290 results Clear all
CVE-2018-1000424 7.8 HIGH EPSS 0.00
Jenkins Artifactory Plugin <2.16.1 - Info Disclosure
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
CWE-522 Jan 09, 2019
CVE-2018-1000423 7.8 HIGH EPSS 0.00
Jenkins Crowd <2.0.0 - Info Disclosure
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
CWE-522 Jan 09, 2019
CVE-2018-1000627 9.8 CRITICAL EPSS 0.00
Battelle V2I Hub 2.5.1 - Info Disclosure
Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this vulnerability to obtain the current API key to gain unauthorized access to the system.
CWE-522 Dec 28, 2018
CVE-2018-11742 9.8 CRITICAL 1 PoC Analysis EPSS 0.41
NEC Univerge Sv9100 Webpro Firmware - Insufficiently Protected Credentials
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
CWE-522 Dec 26, 2018
CVE-2018-20445 9.8 CRITICAL EPSS 0.01
Dlink Dcm-604 Firmware - Insufficiently Protected Credentials
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.32 and iso.3.6.1.4.1.4413.2.2.2.1.5.4.2.4.1.2.32 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20444 9.8 CRITICAL EPSS 0.00
Technicolor Cga0111 Firmware - Insufficiently Protected Credentials
Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20443 9.8 CRITICAL EPSS 0.00
Technicolor Tc7200.d1i Firmware - Insufficiently Protected Credentials
Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20442 9.8 CRITICAL EPSS 0.00
Technicolor Tc7110.b Firmware - Insufficiently Protected Credentials
Technicolor TC7110.B STC8.62.02 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20441 9.8 CRITICAL EPSS 0.00
Technicolor Tc7200.th2v2 Firmware - Insufficiently Protected Credentials
Technicolor TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20440 9.8 CRITICAL EPSS 0.00
Technicolor Cwa0101 Firmware - Insufficiently Protected Credentials
Technicolor CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20439 9.8 CRITICAL EPSS 0.00
Technicolor Dpc3928sl Firmware - Insufficiently Protected Credentials
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-20438 9.8 CRITICAL EPSS 0.00
Technicolor Tc7110.ar Firmware - Insufficiently Protected Credentials
Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.
CWE-522 Dec 25, 2018
CVE-2018-18698 9.8 CRITICAL 1 Writeup EPSS 0.00
Xiaomi Mi-a1 Firmware - Insufficiently Protected Credentials
An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot.
CWE-522 Dec 24, 2018
CVE-2018-20401 9.8 CRITICAL 1 Writeup EPSS 0.01
Zoomtel 5352 Firmware - Insufficiently Protected Credentials
Zoom 5352 v5.5.8.6Y devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20400 9.8 CRITICAL 1 Writeup EPSS 0.01
Ubeeinteractive Dvw2108 Firmware - Insufficiently Protected Credentials
Ubee DVW2108 6.28.1017 and DVW2110 6.28.2012 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20399 9.8 CRITICAL 1 Writeup EPSS 0.03
Motorola Sbg901 Firmware - Insufficiently Protected Credentials
Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20398 9.8 CRITICAL 1 Writeup EPSS 0.01
Skyworthdigital Cm5100 Firmware - Insufficiently Protected Credentials
Skyworth CM5100 V1.1.0, CM5100-440 V1.2.1, CM5100-511 4.1.0.14, CM5100-GHD00 V1.2.2, and CM5100.g2 4.1.0.17 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20397 9.8 CRITICAL 1 Writeup EPSS 0.01
Mplustec Cbc383z Firmware - Insufficiently Protected Credentials
mplus CBC383Z CBC383Z_mplus_MDr026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20396 9.8 CRITICAL 1 Writeup EPSS 0.01
Telaum Ming2120j Firmware - Insufficiently Protected Credentials
NET&SYS MNG2120J 5.76.1006c and MNG6300 5.83.6305jrc2 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20395 9.8 CRITICAL 1 Writeup EPSS 0.01
Net-wave Ming6200 Firmware - Insufficiently Protected Credentials
NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018