CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
8,801 results Clear all
CVE-2025-57992 4.3 MEDIUM EPSS 0.00
InterServer Mail Baby SMTP - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in InterServer Mail Baby SMTP allows Cross Site Request Forgery. This issue affects Mail Baby SMTP: from n/a through 2.8.
CWE-352 Sep 22, 2025
CVE-2025-57983 6.5 MEDIUM EPSS 0.00
Damian BP Disable Activation Reloaded - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Damian BP Disable Activation Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects BP Disable Activation Reloaded: from n/a through 1.2.1.
CWE-352 Sep 22, 2025
CVE-2025-57978 4.3 MEDIUM EPSS 0.00
Themespride Advanced Appointment Booking & Scheduling <1.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in themespride Advanced Appointment Booking &amp; Scheduling allows Cross Site Request Forgery. This issue affects Advanced Appointment Booking &amp; Scheduling: from n/a through 1.9.
CWE-352 Sep 22, 2025
CVE-2025-57977 7.1 HIGH EPSS 0.00
wpdesk Flexible PDF Invoices - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce &amp; WordPress allows Cross Site Request Forgery. This issue affects Flexible PDF Invoices for WooCommerce &amp; WordPress: from n/a through 6.0.13.
CWE-352 Sep 22, 2025
CVE-2025-57970 4.3 MEDIUM EPSS 0.00
SALESmanago & Leadoo <3.8.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in SALESmanago SALESmanago & Leadoo allows Cross Site Request Forgery.This issue affects SALESmanago & Leadoo: from n/a through 3.8.1.
CWE-352 Sep 22, 2025
CVE-2025-57960 4.3 MEDIUM EPSS 0.00
TravelMap <1.0.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map allows Cross Site Request Forgery. This issue affects Travel Map: from n/a through 1.0.3.
CWE-352 Sep 22, 2025
CVE-2025-57946 5.4 MEDIUM EPSS 0.00
Loc Bui payOS - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Loc Bui payOS allows Cross Site Request Forgery. This issue affects payOS: from n/a through 1.0.61.
CWE-352 Sep 22, 2025
CVE-2025-57942 4.3 MEDIUM EPSS 0.00
andy_moyle Emergency Password Reset <9.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 9.0.
CWE-352 Sep 22, 2025
CVE-2025-57934 4.3 MEDIUM EPSS 0.00
LWS Affiliation <2.3.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Aurélien LWS LWS Affiliation allows Cross Site Request Forgery. This issue affects LWS Affiliation: from n/a through 2.3.6.
CWE-352 Sep 22, 2025
CVE-2025-57933 4.3 MEDIUM EPSS 0.00
Piotnet Forms <1.0.30 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in piotnetdotcom Piotnet Forms allows Cross Site Request Forgery. This issue affects Piotnet Forms: from n/a through 1.0.30.
CWE-352 Sep 22, 2025
CVE-2025-57930 4.3 MEDIUM EPSS 0.00
Kanwei Double the Donation <2.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in kanwei_doublethedonation Double the Donation allows Cross Site Request Forgery. This issue affects Double the Donation: from n/a through 2.0.0.
CWE-352 Sep 22, 2025
CVE-2025-57927 4.3 MEDIUM EPSS 0.00
Stephanie Leary Dashboard Notepad - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Notepad allows Cross Site Request Forgery. This issue affects Dashboard Notepad: from n/a through 1.42.
CWE-352 Sep 22, 2025
CVE-2025-57924 4.3 MEDIUM EPSS 0.00
Automattic Developer <1.2.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Developer allows Cross Site Request Forgery. This issue affects Developer: from n/a through 1.2.6.
CWE-352 Sep 22, 2025
CVE-2025-57918 7.1 HIGH EPSS 0.00
ERA404 LinkedInclude <3.0.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude allows Stored XSS. This issue affects LinkedInclude: from n/a through 3.0.4.
CWE-352 Sep 22, 2025
CVE-2025-57915 4.3 MEDIUM EPSS 0.00
TOCHAT.BE - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in César Martín TOCHAT.BE allows Cross Site Request Forgery. This issue affects TOCHAT.BE: from n/a through 1.3.4.
CWE-352 Sep 22, 2025
CVE-2025-57914 4.3 MEDIUM EPSS 0.00
Matat Technologies Deliver via Shipos for WooCommerce <3.0.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Matat Technologies Deliver via Shipos for WooCommerce allows Cross Site Request Forgery. This issue affects Deliver via Shipos for WooCommerce: from n/a through 3.0.2.
CWE-352 Sep 22, 2025
CVE-2025-57905 4.3 MEDIUM EPSS 0.00
AgreeMe Checkboxes For WooCommerce <1.1.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Amin Y AgreeMe Checkboxes For WooCommerce allows Cross Site Request Forgery. This issue affects AgreeMe Checkboxes For WooCommerce: from n/a through 1.1.3.
CWE-352 Sep 22, 2025
CVE-2025-57902 6.5 MEDIUM EPSS 0.00
RIS Version Switcher - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Md Taufiqur Rahman RIS Version Switcher &#8211; Downgrade or Upgrade WP Versions Easily allows Cross Site Request Forgery. This issue affects RIS Version Switcher &#8211; Downgrade or Upgrade WP Versions Easily: from n/a through 1.0.
CWE-352 Sep 22, 2025
CVE-2025-53456 4.3 MEDIUM EPSS 0.00
activewebsight SEO Backlink Monitor - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor allows Cross Site Request Forgery. This issue affects SEO Backlink Monitor: from n/a through 1.6.0.
CWE-352 Sep 22, 2025
CVE-2025-53451 5.4 MEDIUM EPSS 0.00
Mihdan: No External Links <5.1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links allows Cross Site Request Forgery. This issue affects Mihdan: No External Links: from n/a through 5.1.4.
CWE-352 Sep 22, 2025