CVE & Exploit Intelligence Database

Updated 53m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
3 results Clear all
CVE-2025-5689 8.5 HIGH EPSS 0.00
Canonical Authd < 0.5.4 - Improper Privilege Management
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
CWE-269 Jun 16, 2025
CVE-2024-9312 7.5 HIGH EPSS 0.00
Authd <0.3.6 - Privilege Escalation
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
CWE-286 Oct 10, 2024
CVE-2024-9313 8.8 HIGH EPSS 0.01
Authd PAM <0.3.5 - Privilege Escalation
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
Oct 03, 2024