CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
8,801 results Clear all
CVE-2019-25254 8.8 HIGH 1 PoC Analysis EPSS 0.00
KYOCERA Net Admin 3.4.0906 - CSRF
KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user visits the page.
CWE-352 Dec 24, 2025
CVE-2019-25252 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Teradek VidiU Pro 3.0.3 - CSRF
Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page.
CWE-352 Dec 24, 2025
CVE-2019-25250 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
Devolo dLAN 500 AV Wireless+ <3.1.0-1 - CSRF
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a logged-in user visits the site.
CWE-352 Dec 24, 2025
CVE-2019-25247 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
Beward N100 H.264 VGA IP Camera M2.1.6 - CSRF
Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft a malicious web page with a hidden form to add an admin user by tricking a logged-in user into submitting the form.
CWE-352 Dec 24, 2025
CVE-2019-25242 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
FaceSentry Access Control System 6.4.8 - CSRF
FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated users into loading a specially crafted webpage.
CWE-352 Dec 24, 2025
CVE-2019-25238 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
V-SOL GPON/EPON OLT Platform 2.03 - CSRF
V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to create admin users, enable SSH, or modify system settings by tricking authenticated administrators into loading a specially crafted page.
CWE-352 Dec 24, 2025
CVE-2019-25234 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
SmartHouse Webapp 6.5.33 - CSRF/XSS
SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.
CWE-352 Dec 24, 2025
CVE-2019-25233 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
AVE DOMINAplus <1.10.x - XSS, CSRF
AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.
CWE-352 Dec 24, 2025
CVE-2018-25156 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Teradek Cube 7.3.6 - CSRF
Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration interface.
CWE-352 Dec 24, 2025
CVE-2018-25155 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Teradek Slice 7.3.15 - CSRF
Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visits the page.
CWE-352 Dec 24, 2025
CVE-2018-25152 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
Ecessa Edge EV150 10.7.4 - CSRF
Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to add superuser accounts with arbitrary credentials.
CWE-352 Dec 24, 2025
CVE-2018-25151 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Ecessa WANWorx WVR-30 <10.7.4 - CSRF
Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.
CWE-352 Dec 24, 2025
CVE-2018-25150 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
Ecessa ShieldLink SL175EHQ 10.7.4 - CSRF
Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator into loading the page.
CWE-352 Dec 24, 2025
CVE-2018-25149 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Microhard Systems IPn4G 1.1.0 - CSRF
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a specially crafted page.
CWE-352 Dec 24, 2025
CVE-2018-25133 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Synaccess netBooter NP-0801DU 7.4 - CSRF
Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages with hidden form submissions to add admin users by tricking authenticated administrators into loading a malicious page.
CWE-352 Dec 24, 2025
CVE-2018-25127 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
SOCA Access Control System - CSRF
SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that submit forged requests to create admin accounts by tricking logged-in users into visiting a malicious site.
CWE-352 Dec 24, 2025
CVE-2025-68601 8.8 HIGH EPSS 0.00
Rustaurius Five Star Restaurant Reservations <= 2.7.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.7.
CWE-352 Dec 24, 2025
CVE-2025-68584 8.8 HIGH EPSS 0.00
Vimeotheque <2.3.5.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-post-lite allows Cross Site Request Forgery.This issue affects Vimeotheque: from n/a through <= 2.3.5.2.
CWE-352 Dec 24, 2025
CVE-2025-68583 8.8 HIGH EPSS 0.00
Tikweb Management <1.4.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10.
CWE-352 Dec 24, 2025
CVE-2025-68580 8.8 HIGH EPSS 0.00
pluginsware Advanced Classifieds & Directory Pro <=3.2.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9.
CWE-352 Dec 24, 2025