CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
8,801 results Clear all
CVE-2025-14159 4.3 MEDIUM EPSS 0.00
WordPress <4.9.2 - CSRF
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This makes it possible for unauthenticated attackers to export sensitive plugin data including email addresses, IP addresses, physical addresses, user IDs, and other user information via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The exported data is stored in a publicly accessible file, allowing attackers to receive the sensitive information even though they are not authenticated.
CWE-352 Dec 12, 2025
CVE-2025-12407 4.3 MEDIUM EPSS 0.00
WordPress Events Manager - Calendar <7.2.2.2 - CSRF
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to delete locations via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-10684 4.3 MEDIUM EPSS 0.00
Construction Light WordPress <1.6.8 - CSRF
The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .
CWE-287 Dec 12, 2025
CVE-2025-58576 4.3 MEDIUM EPSS 0.00
GroupSession <5.3.0-5.3.2 - CSRF
Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended operations may be performed.
CWE-352 Dec 12, 2025
CVE-2025-14391 4.3 MEDIUM EPSS 0.00
Simple Theme Changer <1.0 - CSRF
The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14354 4.3 MEDIUM EPSS 0.00
WordPress <1.4 - CSRF
The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14165 4.3 MEDIUM EPSS 0.00
Kirim.Email WooCommerce Integration <1.2.9 - CSRF
The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's API credentials and integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14162 4.3 MEDIUM EPSS 0.00
BMLT WordPress Plugin <3.11.4 - CSRF
The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.4. This is due to missing nonce validation on the 'BMLTPlugin_create_option' and 'BMLTPlugin_delete_option ' action. This makes it possible for unauthenticated attackers to create new plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14161 4.3 MEDIUM EPSS 0.00
Truefy Embed <1.1.0 - CSRF
The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'truefy_embed_options_update' settings update action. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14160 4.3 MEDIUM EPSS 0.00
Upcoming for Calendly <1.2.4 - CSRF
The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Calendly API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14158 4.3 MEDIUM EPSS 0.00
WordPress Coding Blocks <1.1.0 - CSRF
The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update plugin settings including the theme configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-14062 4.3 MEDIUM EPSS 0.00
Animated Pixel Marquee Creator <1.0.0 - CSRF
The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' parameter in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the marquee deletion function. This makes it possible for unauthenticated attackers to delete arbitrary marquees via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-13987 4.3 MEDIUM EPSS 0.00
WordPress Purchase & Expense Manager <1.1.2 - CSRF
The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation on the 'sup_pt_handle_deletion' function. This makes it possible for unauthenticated attackers to delete arbitrary purchase records via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-13408 4.3 MEDIUM EPSS 0.00
WordPress Media Optimize Images 2.5.2 - CSRF
The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the foxtool_login_google() function. This makes it possible for unauthenticated attackers to establish an OAuth Connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-13366 4.3 MEDIUM EPSS 0.00
Rabbit Hole WordPress <1.1 - CSRF
The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin's reset functionality. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The vulnerability is exacerbated by the fact that the reset operation is performed via a GET request, making exploitation trivial via image tags or hyperlinks.
CWE-352 Dec 12, 2025
CVE-2025-13363 4.3 MEDIUM EPSS 0.00
IMAQ Core <1.2.1 - CSRF
The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the URL structure settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's URL structure settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Dec 12, 2025
CVE-2025-65472 8.8 HIGH EPSS 0.00
Easyimages2.0 < 2.8.6 - CSRF
A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page.
CWE-352 Dec 11, 2025
CVE-2025-67646 3.5 LOW 1 Writeup EPSS 0.00
MediaWiki TableProgressTracking <1.2.0 - CSRF
TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would trigger unintended authenticated actions through the victim's browser. Due to the lack of token validation, an attacker can delete or track progress against tables. This issue is patched in version 1.2.1 of the extension.
CWE-352 Dec 11, 2025
CVE-2020-36901 8.8 HIGH 1 PoC Analysis EPSS 0.00
UBICOD Medivision Digital Signage 1.5.1 - CSRF
UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.
CWE-352 Dec 10, 2025
CVE-2020-36900 8.8 HIGH 1 PoC Analysis EPSS 0.00
All-Dynamics Digital Signage System 2.0.2 - CSRF
All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when a logged-in user visits the page.
CWE-352 Dec 10, 2025