CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
1,290 results Clear all
CVE-2018-20394 9.8 CRITICAL 1 Writeup EPSS 0.01
Technicolor Dwg849 Firmware - Insufficiently Protected Credentials
Thomson DWG849 STC0.01.16, DWG850-4 ST9C.05.25, DWG855 ST80.20.26, and TWG870 STB2.01.36 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20392 9.8 CRITICAL 1 Writeup EPSS 0.01
Cisco Dpc2100 Firmware - Insufficiently Protected Credentials
S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20391 9.8 CRITICAL 1 Writeup EPSS 0.01
Teknotel Cbw700n Firmware - Insufficiently Protected Credentials
TEKNOTEL CBW700N 81.447.392110.729.024 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20390 9.8 CRITICAL 1 Writeup EPSS 0.01
Kaonmedia Cg2001-an22a Firmware - Insufficiently Protected Credentials
Kaonmedia CG2001-AN22A 1.2.1, CG2001-UDBNA 3.0.8, and CG2001-UN2NA 3.0.8 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20389 9.8 CRITICAL 1 Writeup EPSS 0.01
D-link Dcm-604 Firmware - Insufficiently Protected Credentials
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20388 9.8 CRITICAL 1 Writeup EPSS 0.01
Comtrend Cm-6200un Firmware - Insufficiently Protected Credentials
Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20387 9.8 CRITICAL 1 Writeup EPSS 0.01
Bnmux Bcw700j Firmware - Insufficiently Protected Credentials
Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20386 9.8 CRITICAL 1 Writeup EPSS 0.01
Commscope Arris Sbg6580-2 Firmware - Insufficiently Protected Credentials
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20385 9.8 CRITICAL 1 Writeup EPSS 0.01
Castlenet Cbv38z4ec Firmware - Insufficiently Protected Credentials
CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20384 9.8 CRITICAL 1 Writeup EPSS 0.01
Inovobb Ib-8120-w21 Firmware - Insufficiently Protected Credentials
iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20383 9.8 CRITICAL 1 Writeup EPSS 0.01
Commscope Arris Dg950a Firmware - Insufficiently Protected Credentials
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-20382 9.8 CRITICAL 1 Writeup EPSS 0.01
Jezetek-intl Bcm93383wrg Firmware - Insufficiently Protected Credentials
Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
CWE-522 Dec 23, 2018
CVE-2018-17245 9.8 CRITICAL EPSS 0.00
Kibana <6.5 - Info Disclosure
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.
CWE-201 Dec 20, 2018
CVE-2018-1000851 9.8 CRITICAL EPSS 0.00
Copay Bitcoin Wallet <5.1.0 - Private Key Compromise
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .
CWE-522 Dec 20, 2018
CVE-2018-15717 5.3 MEDIUM EPSS 0.00
Open Dental <18.4 - Info Disclosure
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
CWE-522 Dec 12, 2018
CVE-2018-16791 9.8 CRITICAL EPSS 0.00
SolarWinds SFTP/SCP Server <2018-09-10 - Info Disclosure
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
CWE-522 Dec 05, 2018
CVE-2018-19795 6.8 MEDIUM EPSS 0.00
ChipsBank UMPTool - Info Disclosure
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.
CWE-522 Dec 03, 2018
CVE-2018-16223 9.8 CRITICAL EPSS 0.01
Qbeecam < 1.0.5 - Insufficiently Protected Credentials
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allows an attacker to retrieve the username and password.
CWE-522 Nov 20, 2018
CVE-2018-16222 6.8 MEDIUM EPSS 0.00
Ismartalarm < 2.0.8 - Insufficiently Protected Credentials
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
CWE-522 Nov 20, 2018
CVE-2018-12038 4.2 MEDIUM 1 PoC Analysis EPSS 0.06
Samsung 840 EVO - Privilege Escalation
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.
CWE-522 Nov 20, 2018