CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
93,750 results Clear all
CVE-2025-61616 7.5 HIGH EPSS 0.00
nr modem - DoS
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
CWE-20 Mar 09, 2026
CVE-2025-61615 7.5 HIGH EPSS 0.00
nr modem - DoS
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
CWE-20 Mar 09, 2026
CVE-2025-61614 7.5 HIGH EPSS 0.00
nr modem - DoS
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
CWE-20 Mar 09, 2026
CVE-2025-61613 7.5 HIGH EPSS 0.00
nr modem - DoS
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
CWE-20 Mar 09, 2026
CVE-2025-61612 7.5 HIGH EPSS 0.00
nr modem - DoS
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
CWE-20 Mar 09, 2026
CVE-2025-61611 7.5 HIGH EPSS 0.00
Modem - DoS
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..
CWE-20 Mar 09, 2026
CVE-2025-41772 7.5 HIGH EPSS 0.00
UBR - Info Disclosure
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
CWE-598 Mar 09, 2026
CVE-2025-41767 7.2 HIGH EPSS 0.00
UBR - Privilege Escalation
A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in the web interface of UBR.
CWE-347 Mar 09, 2026
CVE-2025-41766 8.8 HIGH EPSS 0.00
Device - Stack Buffer Overflow
A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.
CWE-787 Mar 09, 2026
CVE-2025-41761 7.8 HIGH EPSS 0.00
UBR Service - Privilege Escalation
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.
CWE-88 Mar 09, 2026
CVE-2025-41758 8.8 HIGH EPSS 0.00
wwupload.cgi - Path Traversal
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.
CWE-22 Mar 09, 2026
CVE-2025-41757 8.8 HIGH EPSS 0.00
UBR - Privilege Escalation
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.
CWE-22 Mar 09, 2026
CVE-2025-41756 8.1 HIGH EPSS 0.00
wwwubr.cgi - Arbitrary File Write
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
CWE-1242 Mar 09, 2026
CVE-2026-3810 8.8 HIGH 1 Writeup EPSS 0.00
Tenda FH1202 1.2.0.14 - Buffer Overflow
A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CWE-119 Mar 09, 2026
CVE-2026-3809 8.8 HIGH 1 Writeup EPSS 0.00
Tenda FH1202 1.2.0.14 - Buffer Overflow
A flaw has been found in Tenda FH1202 1.2.0.14(408). The impacted element is the function fromNatStaticSetting of the file /goform/NatSaticSetting. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.
CWE-119 Mar 09, 2026
CVE-2026-3808 8.8 HIGH 1 Writeup EPSS 0.00
Tenda FH1202 1.2.0.14(408) - Buffer Overflow
A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSiteId results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
CWE-119 Mar 09, 2026
CVE-2026-3823 8.8 HIGH EPSS 0.00
Atop EHG2408 - Buffer Overflow
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CWE-121 Mar 09, 2026
CVE-2026-3807 8.8 HIGH 1 Writeup EPSS 0.00
Tenda FH1202 1.2.0.14 - Buffer Overflow
A security vulnerability has been detected in Tenda FH1202 1.2.0.14(408). Impacted is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Such manipulation of the argument mit_ssid/mit_ssid_index leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CWE-119 Mar 09, 2026
CVE-2026-3804 8.8 HIGH 1 Writeup EPSS 0.00
Tenda i3 1.0.0.6(2204) - Buffer Overflow
A security flaw has been discovered in Tenda i3 1.0.0.6(2204). This vulnerability affects the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet. The manipulation of the argument index results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
CWE-119 Mar 09, 2026
CVE-2026-3803 8.8 HIGH 1 Writeup EPSS 0.00
Tenda i3 1.0.0.6(2204) - Buffer Overflow
A vulnerability was identified in Tenda i3 1.0.0.6(2204). This affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CWE-119 Mar 09, 2026