CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
246 results Clear all
CVE-2017-2766 9.8 CRITICAL EPSS 0.01
EMC Documentum Eroom - Password Reset Weakness
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CWE-640 Feb 03, 2017
CVE-2017-5594 7.5 HIGH 1 PoC Analysis EPSS 0.05
Pagekit < 1.0.10 - Password Reset Weakness
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.
CWE-640 Jan 25, 2017
CVE-2016-7038 7.3 HIGH EPSS 0.00
Moodle < 2.7.15 - Password Reset Weakness
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CWE-640 Jan 20, 2017
CVE-2016-2349 7.5 HIGH EPSS 0.00
BMC Remedy Action Request System - Password Reset Weakness
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
CWE-640 Dec 21, 2016
CVE-2016-5997 6.5 MEDIUM EPSS 0.00
IBM Tealeaf Customer Experience <9.0.1-9.0.2 - Info Disclosure
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-640 Sep 26, 2016
CVE-2016-5996 7.5 HIGH EPSS 0.00
IBM Tealeaf Customer Experience <9.0.1.1117 - Info Disclosure
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length restrictions, which makes it easier for remote attackers to obtain access via a brute-force attack.
CWE-640 Sep 26, 2016