CVE & Exploit Intelligence Database

Updated 54m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
8 results Clear all
CVE-2014-4019 7.5 HIGH EXPLOITED 1 PoC Analysis EPSS 0.52
ZTE ZXV10 W300 - Info Disclosure
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.
CWE-200 Feb 20, 2020
CVE-2015-7259 8.8 HIGH 1 PoC Analysis EPSS 0.33
ZTE Zxv10 W300 Firmware - Credentials Management
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.
CWE-255 Aug 24, 2017
CVE-2015-7258 8.8 HIGH 1 PoC Analysis EPSS 0.33
ZTE Zxv10 W300 Firmware - Credentials Management
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.
CWE-255 Aug 24, 2017
CVE-2015-7257 7.5 HIGH 1 PoC Analysis EPSS 0.17
ZTE Zxv10 W300 Firmware - Password Reset Weakness
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
CWE-640 Aug 24, 2017
CVE-2015-8703 6.5 MEDIUM 1 PoC Analysis EPSS 0.04
ZTE Zxhn H108n R1a Firmware - Information Disclosure
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.
CWE-200 Dec 30, 2015
CVE-2014-4154 1 PoC Analysis EPSS 0.09
ZTE ZXV10 W300 - Info Disclosure
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.
CWE-264 Jul 16, 2014
CVE-2014-4018 1 PoC Analysis EPSS 0.06
ZTE ZXV10 W300 - Info Disclosure
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.
CWE-255 Jul 16, 2014
CVE-2014-4155 1 PoC Analysis EPSS 0.00
ZTE ZXV10 W300 - CSRF
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.
CWE-352 Jun 19, 2014