CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
8,791 results Clear all
CVE-2008-3221 EPSS 0.00
Drupal 6.x <6.3 - CSRF
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
CWE-352 Jul 18, 2008
CVE-2008-3197 EPSS 0.00
phpMyAdmin <2.11.7.1 - CSRF
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
CWE-352 Jul 16, 2008
CVE-2008-3080 1 PoC Analysis EPSS 0.00
Mywebland Mybloggie - CSRF
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.
CWE-352 Jul 09, 2008
CVE-2008-1106 EPSS 0.00
Akamai Client <3322 - CSRF
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.
CWE-287 Jun 09, 2008
CVE-2008-2531 EPSS 0.00
Buildanichestore3 Bans - CSRF
Cross-site scripting (XSS) vulnerability in the search script in Build A Niche Store (BANS) 3.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CWE-352 Jun 03, 2008
CVE-2008-2276 1 PoC Analysis EPSS 0.02
Matisbt Mantis - CSRF
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.
CWE-352 May 16, 2008
CVE-2008-2140 EPSS 0.00
Rpath Appliance Platform Agent - CSRF
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.
CWE-352 May 12, 2008
CVE-2008-2071 EPSS 0.00
Cpanel - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors.
CWE-352 May 12, 2008
CVE-2008-2043 EPSS 0.00
Cpanel - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative actions via (2) frontend/x2/sql/adddb.html, (3) frontend/x2/sql/adduser.html, and (4) frontend/x2/ftp/doaddftp.html.
CWE-352 May 01, 2008
CVE-2008-2002 EPSS 0.00
Motorola Surfboard SB5100-2.3.3.0-SCM00-NOSH - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard reset) via the "Reset All Defaults" value in the BUTTON_INPUT parameter to configdata.html.
CWE-352 Apr 28, 2008
CVE-2008-1981 EPSS 0.00
E-Publish <6.x-1.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
CWE-352 Apr 27, 2008
CVE-2008-1977 EPSS 0.00
Drupal i18n <5.x-2.3 & 6.x-1.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in the Internationalization (i18n) Drupal module 5.x before 5.x-2.3 and 5.x-1.1, and 6.x before 6.x-1.0 beta 1, allows remote attackers to change node translation relationships via unspecified vectors.
CWE-352 Apr 27, 2008
CVE-2008-0165 EPSS 0.00
Ikiwiki < 2.41 - CSRF
Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.
CWE-352 Apr 21, 2008
CVE-2008-1719 EPSS 0.00
Nuke ET <3.4 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET 3.2 and 3.4 allow remote attackers to perform actions as administrators, as demonstrated by inserting an XSS sequence into a document.
CWE-352 Apr 10, 2008
CVE-2008-1654 EPSS 0.28
Adobe Flash - CSRF
Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
CWE-352 Apr 02, 2008
CVE-2008-0164 EPSS 0.00
Plone Cms < 3.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.
CWE-352 Mar 20, 2008
CVE-2007-6708 EPSS 0.00
Cisco Linksys WAG54GS Wireless-G ADSL Gateway <1.01.03 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi.
CWE-352 Mar 13, 2008
CVE-2008-1323 EPSS 0.00
WoltLab Burning Board Lite <2 Beta 1 - CSRF
Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board Lite (wBB) 2 Beta 1 allows remote attackers to delete threads as other users via the ThreadDelete action.
CWE-352 Mar 13, 2008
CVE-2008-1248 EPSS 0.00
Snom 320 SIP Phone - RCE
The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number" field. NOTE: this might overlap CVE-2007-3440.
CWE-352 Mar 10, 2008
CVE-2008-1250 EPSS 0.00
Snom 320 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote attackers to perform actions as the phone user, as demonstrated by inserting an address-book entry containing an XSS sequence.
CWE-352 Mar 10, 2008