CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
8,791 results Clear all
CVE-2008-5941 EPSS 0.00
MODx <0.9.6.1p2 - CSRF
Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.
CWE-352 Jan 22, 2009
CVE-2009-0056 EPSS 0.00
Cisco Ironport Encryption Appliance - CSRF
Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.
CWE-352 Jan 16, 2009
CVE-2009-0055 EPSS 0.00
Cisco Ironport Encryption Appliance - CSRF
Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.
CWE-352 Jan 16, 2009
CVE-2009-0112 EPSS 0.00
PollPro 3.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.
CWE-352 Jan 09, 2009
CVE-2008-5758 EPSS 0.00
PHParanoid <0.5 - CSRF
Cross-site request forgery (CSRF) vulnerability in PHParanoid before 0.5 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors related to private messages.
CWE-352 Dec 30, 2008
CVE-2008-5252 EPSS 0.00
MediaWiki <1.12.2/<1.13.3 - CSRF
Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.
CWE-352 Dec 19, 2008
CVE-2008-5672 EPSS 0.00
PHParanoid <0.4 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in PHParanoid before 0.4 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) admin.php or (2) private messages.
CWE-352 Dec 19, 2008
CVE-2008-5621 1 PoC Analysis EPSS 0.01
phpMyAdmin <3.1.1.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
CWE-352 Dec 17, 2008
CVE-2008-5583 EPSS 0.00
ProjectPier <0.8 - CSRF
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as demonstrated by a delete project action.
CWE-352 Dec 15, 2008
CVE-2008-5568 1 PoC Analysis EPSS 0.00
IPN Pro 3 <1.44 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters.
CWE-352 Dec 15, 2008
CVE-2008-5567 1 PoC Analysis EPSS 0.00
Bonza Cart <1.10 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.
CWE-352 Dec 15, 2008
CVE-2008-5565 1 PoC Analysis EPSS 0.00
DL PayCart <1.34 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.
CWE-352 Dec 15, 2008
CVE-2008-5400 EPSS 0.00
mvnForum <1.2.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers.
CWE-352 Dec 10, 2008
CVE-2008-5382 EPSS 0.00
I-O DATA DEVICE HDL-F160-320 - CSRF
Cross-site request forgery (CSRF) vulnerability in I-O DATA DEVICE HDL-F160, HDL-F250, HDL-F300, and HDL-F320 firmware before 1.02 allows remote attackers to (1) change a configuration or (2) delete files as an authenticated user via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-352 Dec 09, 2008
CVE-2008-5189 EPSS 0.00
Ruby on Rails <2.0.5 - RCE
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
CWE-352 Nov 21, 2008
CVE-2008-5115 1 PoC Analysis EPSS 0.01
SUN Java System Identity Manager - CSRF
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.
CWE-352 Nov 18, 2008
CVE-2008-5113 EPSS 0.00
Wordpress - CSRF
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
CWE-352 Nov 17, 2008
CVE-2008-5028 EPSS 0.01
Nagios < 3.0.4 - CSRF
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.
CWE-352 Nov 10, 2008
CVE-2008-4899 EPSS 0.00
Planetluc Rateme - CSRF
Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
CWE-352 Nov 04, 2008
CVE-2008-3868 EPSS 0.00
Interact 2.4.1 - CSRF
Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super administrators for requests that create super administrator accounts.
CWE-352 Nov 03, 2008