CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
8,791 results Clear all
CVE-2007-5229 1 PoC Analysis EPSS 0.03
Feedburner Feedsmith - CSRF
Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url and (2) feedburner_comments_url parameters.
CWE-352 Oct 05, 2007
CVE-2007-5213 EPSS 0.01
Axis 2100 Network Camera < 2.42 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.
CWE-352 Oct 04, 2007
CVE-2007-5109 EPSS 0.00
Flatnuke - CSRF
Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object to automatically make the request.
CWE-352 Sep 26, 2007
CVE-2007-5060 1 PoC Analysis EPSS 0.00
Xcms - CSRF
Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.
CWE-352 Sep 24, 2007
CVE-2007-5032 EPSS 0.00
Francisco Burzi Php-nuke < 1.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters.
CWE-352 Sep 21, 2007
CVE-2007-4930 3 PoCs Analysis EPSS 0.09
Axis 207w Network Camera - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.
CWE-352 Sep 18, 2007
CVE-2007-4893 EPSS 0.02
Wordpress - CSRF
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
CWE-352 Sep 14, 2007
CVE-2007-4822 EPSS 0.00
Buffalotech Airstation Whr-g54s - CSRF
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filter_ip.html.
CWE-352 Sep 11, 2007
CVE-2007-4724 EPSS 0.01
Apache Tomcat - CSRF
Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.
CWE-352 Sep 05, 2007
CVE-2007-4544 EPSS 0.00
WordPress MU <1.0 - XSS
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).
CWE-352 Aug 27, 2007
CVE-2007-4541 EPSS 0.00
Olate Download <3.4.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.
CWE-352 Aug 27, 2007
CVE-2007-3457 EPSS 0.05
Adobe Flash Player < 8.0.34.0 - CSRF
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
CWE-352 Jul 11, 2007
CVE-2007-3416 EPSS 0.00
Web-app.org Webapp < 0.9.9.6 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9.6; and (b) web-app.net WebAPP 0.9.9.3.3, 0.9.9.3.4, and 2007; allow remote attackers to perform deletions as administrators.
CWE-352 Jun 26, 2007
CVE-2007-2589 EPSS 0.01
SquirrelMail <1.4.9a - CSRF
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.
CWE-352 May 11, 2007
CVE-2007-1520 EPSS 0.01
Phpnuke Php-nuke < 8.0 - CSRF
The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.
CWE-352 Mar 20, 2007
CVE-2007-1489 EPSS 0.01
Web-app.org Webapp - CSRF
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vulnerability.
CWE-352 Mar 16, 2007
CVE-2007-1276 EPSS 0.00
Webmin <1.330, Usermin <1.260 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.
CWE-352 Mar 05, 2007
CVE-2007-1157 EPSS 0.00
JBoss - CSRF
Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.
CWE-352 Mar 02, 2007
CVE-2007-0044 1 PoC Analysis EPSS 0.40
Adobe Acrobat < 7.0.8 - CSRF
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
CWE-352 Jan 03, 2007
CVE-2006-6741 1 PoC Analysis EPSS 0.00
MKPortal - CSRF
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.
CWE-352 Dec 26, 2006