CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
8,801 results Clear all
CVE-2025-62346 6.8 MEDIUM EPSS 0.00
HCL Glovius Cloud - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.
CWE-352 Nov 20, 2025
CVE-2025-12535 5.3 MEDIUM EPSS 0.00
WordPress SureForms <1.13.2 - CSRF
The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs to support unauthenticated form submissions, it incorrectly uses generic REST nonces instead of form-specific nonces. This makes it possible for unauthenticated attackers to bypass CSRF protection on REST API endpoints that rely solely on nonce verification without additional authentication checks, allowing them to trigger unauthorized actions such as the plugin's own post-submission hooks and potentially other plugins' REST endpoints.
CWE-352 Nov 19, 2025
CVE-2025-63955 7.5 HIGH 1 Writeup EPSS 0.00
PHPGurukul Student Record System <3.2 - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
CWE-352 Nov 18, 2025
CVE-2025-59114 6.5 MEDIUM EPSS 0.00
Windu Cms - CSRF
Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send malicious file to the server. Only version 4.1 was tested and confirmed as vulnerable. This issue was fixed in version 4.1 build 2250.
CWE-352 Nov 18, 2025
CVE-2025-59112 6.5 MEDIUM EPSS 0.00
Windu Cms - CSRF
Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send POST request that deletes given user. Only version 4.1 was tested and confirmed as vulnerable. This issue was fixed in version 4.1 build 2250.
CWE-352 Nov 18, 2025
CVE-2025-59110 6.5 MEDIUM EPSS 0.00
Windu Cms - CSRF
Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using CSRF token of other user. It is worth noting that the registration is open and anyone can create an account. Only version 4.1 was tested and confirmed as vulnerable. This issue was fixed in version 4.1 build 2250.
CWE-352 Nov 18, 2025
CVE-2025-6670 8.8 HIGH EPSS 0.00
Wso2 API Control Plane - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective in this context because it allows cookies to be sent with cross-origin top-level navigations using GET requests. A malicious actor can exploit this vulnerability by tricking an authenticated user into visiting a crafted link, leading the browser to issue unintended state-changing requests. Successful exploitation could result in unauthorized operations such as data modification, account changes, or other administrative actions. According to WSO2 Secure Production Guidelines, exposure of Carbon console services to untrusted networks is discouraged, which may reduce the impact in properly secured deployments.
CWE-352 Nov 18, 2025
CVE-2025-9625 4.3 MEDIUM EPSS 0.00
Coil Web Monetization <2.0.2 - CSRF
The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the coil-get-css-selector parameter handling in the maybe_restrict_content function. This makes it possible for unauthenticated attackers to trigger CSS selector detection functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 18, 2025
CVE-2025-12827 4.3 MEDIUM EPSS 0.00
Top Friends WordPress <0.3 - CSRF
The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing nonce validation on the top_friends_options_subpanel() function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 18, 2025
CVE-2025-12406 6.1 MEDIUM EPSS 0.00
WordPress <1.0.1 - CSRF
The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the printAdminPage() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 18, 2025
CVE-2025-12404 6.1 MEDIUM EPSS 0.00
Like-it plugin <2.2 - CSRF
The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the likeit_conf() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 18, 2025
CVE-2025-12173 4.3 MEDIUM EPSS 0.00
WP Admin Microblog <3.1.1 - CSRF
The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf of an administrator via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 18, 2025
CVE-2025-55057 4.5 MEDIUM EPSS 0.00
Maxum Rumpus - Cross-Site Request Forgery
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
CWE-352 Nov 17, 2025
CVE-2025-13283 7.1 HIGH EPSS 0.00
CHT Tenderdoctransfer < 0.41.159 - Absolute Path Traversal
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes.
CWE-36 Nov 17, 2025
CVE-2025-13282 8.1 HIGH EPSS 0.01
CHT Tenderdoctransfer < 0.41.159 - Absolute Path Traversal
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.
CWE-36 Nov 17, 2025
CVE-2025-13179 4.3 MEDIUM EPSS 0.00
Bdtask Wholesale < 2025-10-16 - Missing Authorization
A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-862 Nov 14, 2025
CVE-2025-13177 4.3 MEDIUM EPSS 0.00
Bdtask Saleserp < 2025-10-16 - Missing Authorization
A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-862 Nov 14, 2025
CVE-2025-59480 6.1 MEDIUM EPSS 0.00
Mattermost Mobile < 2.33.0 - CSRF
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses
CWE-352 Nov 13, 2025
CVE-2025-13119 4.3 MEDIUM 1 Writeup EPSS 0.00
Fabian Simple E-banking System - Missing Authorization
A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been published and may be used.
CWE-862 Nov 13, 2025
CVE-2025-64271 6.5 MEDIUM EPSS 0.00
Hasthemes WP Plugin Manager < 1.4.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.
CWE-352 Nov 13, 2025