CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
8,801 results Clear all
CVE-2025-60139 4.3 MEDIUM EPSS 0.00
Joovii Sendle Shipping <6.02 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Joovii Sendle Shipping allows Cross Site Request Forgery. This issue affects Sendle Shipping: from n/a through 6.02.
CWE-352 Sep 26, 2025
CVE-2025-60137 4.3 MEDIUM EPSS 0.00
Galaxy Weblinks Post Featured Video <1.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Post Featured Video allows Cross Site Request Forgery. This issue affects Post Featured Video: from n/a through 1.7.
CWE-352 Sep 26, 2025
CVE-2025-60117 4.3 MEDIUM EPSS 0.00
TangibleWP Vehica Core - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core allows Cross Site Request Forgery. This issue affects Vehica Core: from n/a through 1.0.100.
CWE-352 Sep 26, 2025
CVE-2025-60115 4.3 MEDIUM EPSS 0.00
Instapage Plugin <3.5.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in instapagedev Instapage Plugin allows Cross Site Request Forgery. This issue affects Instapage Plugin: from n/a through 3.5.12.
CWE-352 Sep 26, 2025
CVE-2025-60113 4.3 MEDIUM EPSS 0.00
Groovy Menu <1.4.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu allows Cross Site Request Forgery. This issue affects Groovy Menu: from n/a through 1.4.3.
CWE-352 Sep 26, 2025
CVE-2025-60111 8.8 HIGH EPSS 0.00
Javo Core <3.0.0.266 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core allows Authentication Bypass. This issue affects Javo Core: from n/a through 3.0.0.266.
CWE-352 Sep 26, 2025
CVE-2025-60093 4.3 MEDIUM EPSS 0.00
Shahjada Download Manager - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n/a through 3.3.24.
CWE-352 Sep 26, 2025
CVE-2025-58914 4.3 MEDIUM EPSS 0.00
Di Themes Demo Site Importer - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer allows Cross Site Request Forgery. This issue affects Di Themes Demo Site Importer: from n/a through 1.2.
CWE-352 Sep 26, 2025
CVE-2025-10377 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
WordPress System Dashboard <2.8.20 - CSRF
The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access Logs, Error Logs, and Email Delivery Logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 26, 2025
CVE-2025-10752 4.3 MEDIUM EPSS 0.00
WordPress <6.26.12 - CSRF
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated attackers to forge OAuth authorization requests and potentially hijack the OAuth flow via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 26, 2025
CVE-2025-56311 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Shenzhen C-Data Technology Co. FD602GW-DX-R410 v2.2.14 - CSRF
In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, causes the router to reboot without explicit user consent. This lack of CSRF protection on a sensitive administrative function can lead to denial of service by disrupting network availability.
CWE-352 Sep 23, 2025
CVE-2025-59572 8.8 HIGH EPSS 0.00
purethemes WorkScout-Core - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core allows Cross Site Request Forgery. This issue affects WorkScout-Core: from n/a through n/a.
CWE-352 Sep 22, 2025
CVE-2025-59568 4.3 MEDIUM EPSS 0.00
Zoho Flow <2.14.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow allows Cross Site Request Forgery. This issue affects Zoho Flow: from n/a through 2.14.1.
CWE-352 Sep 22, 2025
CVE-2025-58956 7.1 HIGH EPSS 0.00
loopus WP Attractive Donations System - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System allows Stored XSS. This issue affects WP Attractive Donations System: from n/a through n/a.
CWE-352 Sep 22, 2025
CVE-2025-58690 7.1 HIGH EPSS 0.00
ptibogxiv Doliconnect <9.5.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect allows Stored XSS. This issue affects Doliconnect: from n/a through 9.5.7.
CWE-352 Sep 22, 2025
CVE-2025-58688 7.1 HIGH EPSS 0.00
Casengo Live Chat Support <2.1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support allows Stored XSS. This issue affects Casengo Live Chat Support: from n/a through 2.1.4.
CWE-352 Sep 22, 2025
CVE-2025-58687 7.1 HIGH EPSS 0.00
WP CMS Ninja Current Age Plugin <1.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin allows Stored XSS. This issue affects Current Age Plugin: from n/a through 1.6.
CWE-352 Sep 22, 2025
CVE-2025-58677 7.1 HIGH EPSS 0.00
ShrinkTheWeb <2.8.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS. This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through 2.8.5.
CWE-352 Sep 22, 2025
CVE-2025-58676 7.1 HIGH EPSS 0.00
extendyourweb HORIZONTAL SLIDER -<2.4 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS. This issue affects HORIZONTAL SLIDER: from n/a through 2.4.
CWE-352 Sep 22, 2025
CVE-2025-58675 4.3 MEDIUM EPSS 0.00
tryinteract Interact: Embed A Quiz On Your Site <3.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site allows Cross Site Request Forgery. This issue affects Interact: Embed A Quiz On Your Site: from n/a through 3.1.
CWE-352 Sep 22, 2025