CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
8,791 results Clear all
CVE-2008-1260 EPSS 0.00
Zyxel P-2602HW-D1A 3.40(AJZ.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.
CWE-352 Mar 10, 2008
CVE-2008-1254 EPSS 0.00
ZyXEL P-660HW - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
CWE-352 Mar 10, 2008
CVE-2008-1172 EPSS 0.00
TorrentTrader Classic 1.08 - CSRF
Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages.
CWE-352 Mar 06, 2008
CVE-2008-1149 EPSS 0.01
phpMyAdmin <2.11.5 - CSRF & SQL Injection
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
CWE-352 Mar 04, 2008
CVE-2008-0556 EPSS 0.00
Openca Pki < 0.9.2.5 - CSRF
Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users via a link or IMG tag to RAServer.
CWE-352 Feb 19, 2008
CVE-2008-0788 EPSS 0.00
Mybb < 1.2.11 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.
CWE-352 Feb 15, 2008
CVE-2008-0575 EPSS 0.00
Webspell - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action.
CWE-352 Feb 05, 2008
CVE-2008-0571 EPSS 0.00
Drupal Userpoints Module - CSRF
The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and manipulate points.
CWE-352 Feb 05, 2008
CVE-2008-0563 EPSS 0.00
Liferay Enterprise Portal - CSRF
Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.
CWE-352 Feb 05, 2008
CVE-2008-0182 EPSS 0.00
Liferay Enterprise Portal < 4.3.6 - CSRF
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.
CWE-352 Feb 05, 2008
CVE-2008-0524 EPSS 0.00
Yamaha Rt107e - CSRF
Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.
CWE-352 Jan 31, 2008
CVE-2008-0508 EPSS 0.00
Wordpress Permalinks Migration Plugin - CSRF
Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.
CWE-352 Jan 31, 2008
CVE-2008-0471 EPSS 0.00
Phpbb - CSRF
Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.
CWE-352 Jan 29, 2008
CVE-2008-0472 EPSS 0.00
Woltlab Burning Board - CSRF
Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.
CWE-352 Jan 29, 2008
CVE-2008-0336 EPSS 0.00
Bugtracker.net < 2.7.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.
CWE-352 Jan 17, 2008
CVE-2008-0272 EPSS 0.00
Drupal - CSRF
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.
CWE-352 Jan 15, 2008
CVE-2008-0266 1 PoC Analysis EPSS 0.00
Eticket - CSRF
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.
CWE-352 Jan 15, 2008
CVE-2008-0271 EPSS 0.00
Drupal Bueditor < 4.7.x-1.0 - CSRF
The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.
CWE-352 Jan 15, 2008
CVE-2007-6420 EPSS 0.05
Apache HTTP Server 2.2.x - CSRF
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
CWE-352 Jan 12, 2008
CVE-2008-0228 1 PoC Analysis EPSS 0.01
Linksys Wrt54gl - CSRF
Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.
CWE-352 Jan 10, 2008