CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
8,801 results Clear all
CVE-2025-13737 4.3 MEDIUM EPSS 0.00
Nextend Social Login & Register <3.1.21 - CSRF
The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 28, 2025
CVE-2025-13143 4.3 MEDIUM EPSS 0.00
Poll, Survey & Quiz Maker Plugin <19.12.0 - CSRF
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers to disconnect the site from the Opinion Stage platform integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 27, 2025
CVE-2025-12578 4.3 MEDIUM EPSS 0.00
Reuters Direct <3.0.0 - CSRF
The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the 'class-reuters-direct-settings.php' page. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 27, 2025
CVE-2025-62593 EXPLOITED 1 Writeup EPSS 0.00
Pypi Ray < 2.52.0 - Code Injection
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
CWE-352 Nov 26, 2025
CVE-2025-12061 8.6 HIGH EPSS 0.00
TAX SERVICE Electronic HDM <1.2.1 - SQL Injection
The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements
CWE-862 Nov 26, 2025
CVE-2025-60739 9.6 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
Ilevia EVE X1 Server <4.7.18.0.eden-2025_07_21 - CSRF
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component
CWE-352 Nov 25, 2025
CVE-2025-12587 4.3 MEDIUM EPSS 0.00
Peer Publish <1.0 - CSRF
The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the website management pages. This makes it possible for unauthenticated attackers to add, modify, or delete website configurations via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Nov 25, 2025
CVE-2025-12586 4.3 MEDIUM EPSS 0.00
WordPress plugin - CSRF
The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation when toggling the maintenance mode status. This makes it possible for unauthenticated attackers to enable or disable the site's maintenance mode via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Nov 25, 2025
CVE-2025-62497 6.5 MEDIUM EPSS 0.00
Sony Snc-cx600w Firmware < 2.8.0 - CSRF
Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may be performed.
CWE-352 Nov 25, 2025
CVE-2025-56400 8.8 HIGH EPSS 0.00
Tuya Smartlife < 6.5.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.
CWE-352 Nov 24, 2025
CVE-2025-63953 6.5 MEDIUM 1 Writeup EPSS 0.00
Magewell Pro Convert <1.2.213 - CSRF
A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
CWE-352 Nov 24, 2025
CVE-2025-63952 5.7 MEDIUM 1 Writeup EPSS 0.00
Magewell Pro Convert <1.2.213 - CSRF
A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
CWE-352 Nov 24, 2025
CVE-2025-65107 6.5 MEDIUM EPSS 0.00
Langfuse < 2.95.12 - Improper Authorization
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_<PROVIDER>_CHECK setting, a potential account takeover may happen if an authenticated user is made to call a specifically crafted URL via a CSRF or phishing attack. This issue has been patched in versions 2.95.12 and 3.131.0. A workaround for this issue involves setting AUTH_<PROVIDER>_CHECK.
CWE-285 Nov 21, 2025
CVE-2025-11087 8.8 HIGH EPSS 0.00
Zegen Core <2.0.1 - CSRF
The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing nonce validation and missing file type validation in the '/custom-font-code/custom-fonts-uploads.php' file. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 21, 2025
CVE-2025-66097 4.3 MEDIUM EPSS 0.00
I Order Terms <=1.5.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Igor Jerosimić I Order Terms i-order-terms allows Cross Site Request Forgery.This issue affects I Order Terms: from n/a through <= 1.5.0.
CWE-352 Nov 21, 2025
CVE-2025-66064 5.3 MEDIUM EPSS 0.00
RafflePress <1.12.20 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.
CWE-352 Nov 21, 2025
CVE-2025-66061 4.3 MEDIUM EPSS 0.00
Seriously Simple Podcasting <3.13.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
CWE-352 Nov 21, 2025
CVE-2025-13142 4.3 MEDIUM EPSS 0.00
Custom Post Type <1.0 - CSRF
The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the custom post type deletion functionality. This makes it possible for unauthenticated attackers to delete custom post types via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 21, 2025
CVE-2025-13134 6.1 MEDIUM EPSS 0.00
AuthorSure WordPress <2.3 - CSRF
The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the 'authorsure' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 21, 2025
CVE-2025-62687 6.5 MEDIUM EPSS 0.00
Secuavail Logstare Collector < 2.4.2 - CSRF
Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.
CWE-352 Nov 21, 2025