CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
8,801 results Clear all
CVE-2020-36906 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - CSRF
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted form.
CWE-352 Jan 06, 2026
CVE-2025-53344 4.3 MEDIUM EPSS 0.00
ThimPress Thim Core - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affects Thim Core: from n/a through 2.3.3.
CWE-352 Jan 05, 2026
CVE-2025-67315 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Phpgurukul Employee Leave Management System - CSRF
Cross Site Request Forgery vulnerability in Employee Leave Management System v.2.1 allows a remote attacker to escalate privileges via the manage-employee.php component
CWE-352 Jan 05, 2026
CVE-2023-52212 5.4 MEDIUM EPSS 0.00
Automattic WP Job Manager - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n/a through 2.0.0.
CWE-352 Jan 05, 2026
CVE-2026-21430 9.3 CRITICAL EPSS 0.00
Emlog - CSRF
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
CWE-352 Jan 02, 2026
CVE-2025-15405 4.3 MEDIUM EPSS 0.00
Phpems < 11.0 - Missing Authorization
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.
CWE-352 Jan 01, 2026
CVE-2025-31054 7.1 HIGH EPSS 0.00
Themefy Bloggie <2.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.
CWE-352 Dec 31, 2025
CVE-2025-62123 4.3 MEDIUM EPSS 0.00
Ink themes WP Gmail SMTP <1.0.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ink themes WP Gmail SMTP allows Cross Site Request Forgery.This issue affects WP Gmail SMTP: from n/a through 1.0.7.
CWE-352 Dec 31, 2025
CVE-2025-62113 4.3 MEDIUM EPSS 0.00
Co-marquage service-public.Fr - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.Fr allows Cross Site Request Forgery.This issue affects Co-marquage service-public.Fr: from n/a through 0.5.77.
CWE-352 Dec 31, 2025
CVE-2025-62101 4.3 MEDIUM EPSS 0.00
Pardakht Delkhah - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Omid Shamloo Pardakht Delkhah allows Cross Site Request Forgery.This issue affects Pardakht Delkhah: from n/a through 3.0.0.
CWE-352 Dec 31, 2025
CVE-2025-63040 4.3 MEDIUM EPSS 0.00
Saad Iqbal Post Snippets <4.0.11 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through 4.0.11.
CWE-352 Dec 31, 2025
CVE-2025-63014 4.3 MEDIUM EPSS 0.00
Gmedia Photo Gallery <1.24.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through 1.24.1.
CWE-352 Dec 31, 2025
CVE-2025-62148 4.3 MEDIUM EPSS 0.00
Eugen Bobrowski Robots.Txt <1.6.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Eugen Bobrowski Robots.Txt rewrite allows Cross Site Request Forgery.This issue affects Robots.Txt rewrite: from n/a through 1.6.1.
CWE-352 Dec 31, 2025
CVE-2025-62133 4.3 MEDIUM EPSS 0.00
Manidoraisamy FormFacade <1.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Manidoraisamy FormFacade allows Cross Site Request Forgery.This issue affects FormFacade: from n/a through 1.4.1.
CWE-352 Dec 31, 2025
CVE-2025-62089 4.3 MEDIUM EPSS 0.00
Mergado Pack <4.2.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Cross Site Request Forgery.This issue affects Mergado Pack: from n/a through 4.2.0.
CWE-352 Dec 31, 2025
CVE-2025-62084 4.3 MEDIUM EPSS 0.00
Imdad Next Web iNext Woo Pincode Checker <2.3.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Imdad Next Web iNext Woo Pincode Checker allows Cross Site Request Forgery.This issue affects iNext Woo Pincode Checker: from n/a through 2.3.1.
CWE-352 Dec 31, 2025
CVE-2025-62080 4.3 MEDIUM EPSS 0.00
Channelize.Io Team Live Shopping & Shoppable Videos For WooCommerce...
Cross-Site Request Forgery (CSRF) vulnerability in Channelize.Io Team Live Shopping & Shoppable Videos For WooCommerce allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through 2.2.0.
CWE-352 Dec 31, 2025
CVE-2025-59130 4.3 MEDIUM EPSS 0.00
Appointify <1.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Appointify allows Cross Site Request Forgery.This issue affects Appointify: from n/a through 1.0.8.
CWE-352 Dec 31, 2025
CVE-2025-62134 5.4 MEDIUM EPSS 0.00
A WP Life Contact Form Widget <1.5.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through 1.5.1.
CWE-352 Dec 31, 2025
CVE-2025-62120 5.4 MEDIUM EPSS 0.00
Rick Beckman OpenHook - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Rick Beckman OpenHook allows Cross Site Request Forgery.This issue affects OpenHook: from n/a through 4.3.1.
CWE-352 Dec 31, 2025