CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
8,801 results Clear all
CVE-2025-58869 6.5 MEDIUM EPSS 0.00
SimaCookie <1.3.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Simasicher SimaCookie allows Stored XSS. This issue affects SimaCookie: from n/a through 1.3.2.
CWE-352 Sep 05, 2025
CVE-2025-58865 4.3 MEDIUM EPSS 0.00
reimund Compact Admin <1.3.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in reimund Compact Admin allows Cross Site Request Forgery. This issue affects Compact Admin: from n/a through 1.3.0.
CWE-352 Sep 05, 2025
CVE-2025-58861 7.1 HIGH EPSS 0.00
WP Corner Quick Event Calendar <1.4.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored XSS. This issue affects Quick Event Calendar: from n/a through 1.4.9.
CWE-352 Sep 05, 2025
CVE-2025-58860 7.1 HIGH EPSS 0.00
KaizenCoders Enable Latex <1.2.16 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex allows Stored XSS. This issue affects Enable Latex: from n/a through 1.2.16.
CWE-352 Sep 05, 2025
CVE-2025-58859 7.1 HIGH EPSS 0.00
Add to Feedly <1.2.11 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Add to Feedly allows Stored XSS. This issue affects Add to Feedly: from n/a through 1.2.11.
CWE-352 Sep 05, 2025
CVE-2025-58856 6.5 MEDIUM EPSS 0.00
Woocommerce Notify Updated Product <1.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product allows Stored XSS. This issue affects Woocommerce Notify Updated Product: from n/a through 1.6.
CWE-352 Sep 05, 2025
CVE-2025-58854 7.1 HIGH EPSS 0.00
Samer Bechara Ultimate AJAX Login <1.2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login allows Reflected XSS. This issue affects Ultimate AJAX Login: from n/a through 1.2.1.
CWE-352 Sep 05, 2025
CVE-2025-58853 7.1 HIGH EPSS 0.00
OTWthemes Popping Sidebars and Widgets Light <1.27 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light allows Reflected XSS. This issue affects Popping Sidebars and Widgets Light: from n/a through 1.27.
CWE-352 Sep 05, 2025
CVE-2025-58852 7.1 HIGH EPSS 0.00
MSTW League Manager <2.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager allows Stored XSS. This issue affects MSTW League Manager: from n/a through 2.10.
CWE-352 Sep 05, 2025
CVE-2025-58849 7.1 HIGH EPSS 0.00
Hide Real Download Path <1.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path allows Stored XSS. This issue affects Hide Real Download Path: from n/a through 1.6.
CWE-352 Sep 05, 2025
CVE-2025-58848 7.1 HIGH EPSS 0.00
aakash1911 WP likes <3.1.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes allows Reflected XSS. This issue affects WP likes: from n/a through 3.1.1.
CWE-352 Sep 05, 2025
CVE-2025-58847 7.1 HIGH EPSS 0.00
Yaidier WN Flipbox Pro - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS. This issue affects WN Flipbox Pro: from n/a through 2.1.
CWE-352 Sep 05, 2025
CVE-2025-58846 7.1 HIGH EPSS 0.00
WordPress Buffer - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Dejan Markovic WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule allows Reflected XSS. This issue affects WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule: from n/a through 2020.1.0.
CWE-352 Sep 05, 2025
CVE-2025-58845 7.1 HIGH EPSS 0.00
ChrisHurst Bulk Watermark -n/a-1.6.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ChrisHurst Bulk Watermark allows Reflected XSS. This issue affects Bulk Watermark: from n/a through 1.6.10.
CWE-352 Sep 05, 2025
CVE-2025-58844 7.1 HIGH EPSS 0.00
Subhash Kumar Database to Excel <1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Subhash Kumar Database to Excel allows Stored XSS. This issue affects Database to Excel: from n/a through 1.0.
CWE-352 Sep 05, 2025
CVE-2025-58843 7.1 HIGH EPSS 0.00
Auto Last Youtube Video <1.0.8 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Auto Last Youtube Video allows Stored XSS. This issue affects Auto Last Youtube Video: from n/a through 1.0.7.
CWE-352 Sep 05, 2025
CVE-2025-58833 8.8 HIGH EPSS 0.00
INVELITY MyGLS connect <1.1.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in INVELITY Invelity MyGLS connect allows Object Injection. This issue affects Invelity MyGLS connect: from n/a through 1.1.1.
CWE-352 Sep 05, 2025
CVE-2025-58831 4.3 MEDIUM EPSS 0.00
Parallax Scrolling Enllax.js - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in snagysandor Parallax Scrolling Enllax.js allows Cross Site Request Forgery. This issue affects Parallax Scrolling Enllax.js: from n/a through 0.0.6.
CWE-352 Sep 05, 2025
CVE-2025-58818 5.4 MEDIUM EPSS 0.00
SwiftNinjaPro Developer Tools Blocker <3.2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in SwiftNinjaPro Developer Tools Blocker allows Cross Site Request Forgery. This issue affects Developer Tools Blocker: from n/a through 3.2.1.
CWE-352 Sep 05, 2025
CVE-2025-58809 7.1 HIGH EPSS 0.00
To Lead For Salesforce <2.7.3.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce allows Reflected XSS. This issue affects To Lead For Salesforce: from n/a through 2.7.3.9.
CWE-352 Sep 05, 2025