CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
8,801 results Clear all
CVE-2025-62117 5.4 MEDIUM EPSS 0.00
Jayce53 EasyIndex <1.1.1704 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n/a through 1.1.1704.
CWE-352 Dec 31, 2025
CVE-2025-62992 6.5 MEDIUM EPSS 0.00
Everest Backup <2.3.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Everest themes Everest Backup allows Path Traversal.This issue affects Everest Backup: from n/a through 2.3.9.
CWE-352 Dec 31, 2025
CVE-2025-49028 7.1 HIGH EPSS 0.00
Zoho Mail <3.3.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through 3.3.1.
CWE-352 Dec 31, 2025
CVE-2025-68885 7.1 HIGH EPSS 0.00
Page Carbajal Custom Post Status <1.1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS.This issue affects Custom Post Status: from n/a through 1.1.0.
CWE-352 Dec 31, 2025
CVE-2025-49354 7.1 HIGH EPSS 0.00
Mindstien Technologies - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category allows Stored XSS.This issue affects Recent Posts From Each Category: from n/a through 1.4.
CWE-352 Dec 31, 2025
CVE-2025-49353 7.1 HIGH EPSS 0.00
Marcin Kijak Noindex <1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path allows Stored XSS.This issue affects Noindex by Path: from n/a through 1.0.
CWE-352 Dec 31, 2025
CVE-2025-49345 7.1 HIGH EPSS 0.00
WP-EasyArchives <3.1.2 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives allows Stored XSS.This issue affects WP-EasyArchives: from n/a through 3.1.2.
CWE-352 Dec 31, 2025
CVE-2025-49344 7.1 HIGH EPSS 0.00
Rene Ade SensitiveTagCloud <1.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Rene Ade SensitiveTagCloud allows Stored XSS.This issue affects SensitiveTagCloud: from n/a through 1.4.1.
CWE-352 Dec 31, 2025
CVE-2025-49343 7.1 HIGH EPSS 0.00
Social Profilr - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Socialprofilr Social Profilr allows Stored XSS.This issue affects Social Profilr: from n/a through 1.0.
CWE-352 Dec 31, 2025
CVE-2025-49342 7.1 HIGH EPSS 0.00
Custom Style <=1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Häfelinger Custom Style allows Stored XSS.This issue affects Custom Style: from n/a through 1.0.
CWE-352 Dec 31, 2025
CVE-2025-59137 7.1 HIGH EPSS 0.00
eLEOPARD Behance Portfolio Manager <1.7.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in eLEOPARD Behance Portfolio Manager allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through 1.7.5.
CWE-352 Dec 31, 2025
CVE-2025-49346 7.1 HIGH EPSS 0.00
Peter Sterling Simple Archive Generator <5.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS.This issue affects Simple Archive Generator: from n/a through 5.2.
CWE-352 Dec 31, 2025
CVE-2025-59131 7.1 HIGH EPSS 0.00
Hoernerfranz WP-CalDav2ICS -<1.3.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Hoernerfranz WP-CalDav2ICS allows Stored XSS.This issue affects WP-CalDav2ICS: from n/a through 1.3.4.
CWE-352 Dec 30, 2025
CVE-2022-50804 8.8 HIGH EPSS 0.00
JM-DATA ONU JF511-TV <1.0.67 - CSRF
JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.
CWE-352 Dec 30, 2025
CVE-2025-62112 4.3 MEDIUM EPSS 0.00
Merv Barrett Import into Easy Property Listings <2.2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings allows Cross Site Request Forgery.This issue affects Import into Easy Property Listings: from n/a through 2.2.1.
CWE-352 Dec 30, 2025
CVE-2025-52835 9.6 CRITICAL EPSS 0.00
ConoHa by GMO WING WordPress Migrator - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through 1.1.9.
CWE-352 Dec 30, 2025
CVE-2025-69021 5.4 MEDIUM EPSS 0.00
Ays Pro Popup box <=6.0.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 6.0.7.
CWE-352 Dec 30, 2025
CVE-2025-68998 5.4 MEDIUM EPSS 0.00
Heateor Social Login <1.1.40 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39.
CWE-352 Dec 30, 2025
CVE-2024-30855 8.8 HIGH 1 Writeup EPSS 0.00
Dedecms - CSRF
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
CWE-352 Dec 29, 2025
CVE-2025-67013 6.5 MEDIUM 1 Writeup EPSS 0.00
Etlsystems D0116s1ula-22454 Firmware - CSRF
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.
CWE-352 Dec 26, 2025