CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
8,801 results Clear all
CVE-2025-8383 4.3 MEDIUM EPSS 0.00
Depicter plugin <4.0.4 - CSRF
The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Oct 31, 2025
CVE-2023-53688 5.4 MEDIUM EPSS 0.00
Nagios XI <5.11.3 - XSS/CSRF
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that executes in the context of a victim's browser (XSS). Additionally, the component does not enforce sufficient anti-CSRF protections on state-changing operations, enabling an attacker to induce authenticated users to perform unwanted actions.
CWE-352 Oct 30, 2025
CVE-2025-10317 EPSS 0.00
Quick.Cart - CSRF
Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious product with content defined by the attacker. This software does not implement any protection against this type of attack. All forms available in this software are potentially vulnerable. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CWE-352 Oct 30, 2025
CVE-2025-10930 4.3 MEDIUM EPSS 0.00
2bits Currency < 8.x-3.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0.
CWE-352 Oct 30, 2025
CVE-2025-62797 1 Writeup EPSS 0.00
FluxCP - CSRF
FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the FluxCP-based website template used by multiple rAthena/Ragnarok servers. State-changing POST endpoints accept browser-initiated requests that are authorized solely by the session cookie without per-request anti-CSRF tokens or robust Origin/Referer validation. An attacker who can lure a logged-in user to an attacker-controlled page can cause that user to perform sensitive actions without their intent. This vulnerability is fixed with commit e3f130c.
CWE-352 Oct 29, 2025
CVE-2025-12479 8.8 HIGH EPSS 0.00
Azure-access Blu-ic2 Firmware < 1.20 - CSRF
Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CWE-352 Oct 29, 2025
CVE-2025-64149 5.4 MEDIUM EPSS 0.00
Jenkins Publish TO Bitbucket < 0.4 - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CWE-352 Oct 29, 2025
CVE-2025-64141 4.3 MEDIUM EPSS 0.00
Jenkins Nexus Task Runner < 0.9.2 - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
CWE-352 Oct 29, 2025
CVE-2025-64138 4.3 MEDIUM EPSS 0.00
Jenkins Start Windocks Container < 1.4 - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.
CWE-352 Oct 29, 2025
CVE-2025-64136 4.3 MEDIUM EPSS 0.00
Jenkins Themis < 1.4.1 - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.
CWE-352 Oct 29, 2025
CVE-2025-64133 5.4 MEDIUM EPSS 0.00
Jenkins Extensible Choice Parameter < 239.v5f5c278708cf - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.
CWE-352 Oct 29, 2025
CVE-2024-45161 4.6 MEDIUM EPSS 0.00
Blu-Castle BCUM221E 1.0.0P220507 - CSRF
A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via a URL, an image load, an XMLHttpRequest, etc. and can result in exposure of data or unintended code execution.
CWE-352 Oct 29, 2025
CVE-2025-64290 4.3 MEDIUM EPSS 0.00
Premmerce Product Search <2.2.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Cross Site Request Forgery.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.
CWE-352 Oct 29, 2025
CVE-2025-64288 4.3 MEDIUM EPSS 0.00
Premmerce - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This issue affects Premmerce: from n/a through <= 1.3.19.
CWE-352 Oct 29, 2025
CVE-2025-64286 4.3 MEDIUM EPSS 0.00
WpEstate WP Rentals <4.14 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1.
CWE-352 Oct 29, 2025
CVE-2025-64226 4.3 MEDIUM EPSS 0.00
colabrio Stockie Extra <= 1.2.11 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in colabrio Stockie Extra stockie-extra allows Cross Site Request Forgery.This issue affects Stockie Extra: from n/a through <= 1.2.11.
CWE-352 Oct 29, 2025
CVE-2025-64201 4.3 MEDIUM EPSS 0.00
PowerPress Podcasting <11.13.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
CWE-352 Oct 29, 2025
CVE-2025-60075 7.1 HIGH EPSS 0.00
Allegro Marketing hpb seo <3.0.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from n/a through <= 3.0.1.
CWE-352 Oct 29, 2025
CVE-2025-58939 4.3 MEDIUM EPSS 0.00
Super Store Finder <8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
CWE-352 Oct 29, 2025
CVE-2025-57931 5.3 MEDIUM EPSS 0.00
Ays Pro Popup box <5.5.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through 5.5.4.
CWE-352 Oct 29, 2025