CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
8,801 results Clear all
CVE-2025-58807 7.1 HIGH EPSS 0.00
Dsingh Purge Varnish Cache <2.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.
CWE-352 Sep 05, 2025
CVE-2025-58806 7.1 HIGH EPSS 0.00
imjoehaines WordPress Error Monitoring <1.6.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in imjoehaines WordPress Error Monitoring by Bugsnag allows Stored XSS. This issue affects WordPress Error Monitoring by Bugsnag: from n/a through 1.6.3.
CWE-352 Sep 05, 2025
CVE-2025-58804 4.3 MEDIUM EPSS 0.00
WooCommerce Single Page Checkout <1.2.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout allows Cross Site Request Forgery. This issue affects WooCommerce Single Page Checkout: from n/a through 1.2.7.
CWE-352 Sep 05, 2025
CVE-2025-58802 4.3 MEDIUM EPSS 0.00
TrustMate.io - WooCommerce <1.14.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration allows Cross Site Request Forgery. This issue affects TrustMate.io – WooCommerce integration: from n/a through 1.14.0.
CWE-352 Sep 05, 2025
CVE-2025-58801 5.4 MEDIUM EPSS 0.00
KCS Responder <4.3.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in KCS Responder allows Cross Site Request Forgery. This issue affects Responder: from n/a through 4.3.8.
CWE-352 Sep 05, 2025
CVE-2025-58800 4.3 MEDIUM EPSS 0.00
WP Email Template <2.8.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template allows Cross Site Request Forgery. This issue affects WP Email Template: from n/a through 2.8.3.
CWE-352 Sep 05, 2025
CVE-2025-58799 4.3 MEDIUM EPSS 0.00
Custom WooCommerce Checkout Fields Editor <1.3.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor allows Cross Site Request Forgery. This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.4.
CWE-352 Sep 05, 2025
CVE-2025-58798 4.3 MEDIUM EPSS 0.00
Bjorn Manintveld BCM Duplicate Menu - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Bjorn Manintveld BCM Duplicate Menu allows Cross Site Request Forgery. This issue affects BCM Duplicate Menu: from n/a through 1.1.2.
CWE-352 Sep 05, 2025
CVE-2025-58794 4.3 MEDIUM EPSS 0.00
Notification for Telegram <3.4.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram allows Cross Site Request Forgery. This issue affects Notification for Telegram: from n/a through 3.4.6.
CWE-352 Sep 05, 2025
CVE-2025-58792 4.3 MEDIUM EPSS 0.00
WPKube Authors List <2.0.6.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List allows Cross Site Request Forgery. This issue affects Authors List: from n/a through 2.0.6.1.
CWE-352 Sep 05, 2025
CVE-2025-9616 5.3 MEDIUM EPSS 0.00
PopAd plugin <1.0.4 - CSRF
The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the PopAd_reset_cookie_time function. This makes it possible for unauthenticated attackers to reset cookie time settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 04, 2025
CVE-2025-20326 4.3 MEDIUM EPSS 0.00
Cisco Unified CM - CSRF
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.
CWE-352 Sep 03, 2025
CVE-2025-58611 4.3 MEDIUM EPSS 0.00
Tickera <3.5.5.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Tickera Tickera allows Cross Site Request Forgery. This issue affects Tickera: from n/a through 3.5.5.6.
CWE-352 Sep 03, 2025
CVE-2025-58272 3.7 LOW EPSS 0.00
Web Caster V130 <1.08 - CSRF
Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
CWE-352 Sep 03, 2025
CVE-2025-0610 8.6 HIGH EPSS 0.00
Akınsoft QR Menü <1.05.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery.This issue affects QR Menü: from s1.05.06 before v1.05.12.
CWE-352 Sep 01, 2025
CVE-2025-9747 4.3 MEDIUM 1 Writeup EPSS 0.00
Benjaminjonard Koillection < 1.7.0 - Missing Authorization
A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 is able to address this issue. The name of the patch is 9ab8562d3f1e953da93fed63f9ee802c7ea26a9a. It is suggested to upgrade the affected component. The vendor explains: "I ended up switching to a newer CSRF handling using stateless token."
CWE-862 Aug 31, 2025
CVE-2025-9618 4.3 MEDIUM EPSS 0.00
WordPress Related Posts Lite <1.12 - CSRF
The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 30, 2025
CVE-2025-9374 4.3 MEDIUM EPSS 0.00
WordPress Ultimate Tag Warrior Importer <0.3 - CSRF
The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 29, 2025
CVE-2025-48363 4.3 MEDIUM EPSS 0.00
Popup for CF7 with Sweet Alert <1.6.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Metin Saraç Popup for CF7 with Sweet Alert allows Cross Site Request Forgery. This issue affects Popup for CF7 with Sweet Alert: from n/a through 1.6.5.
CWE-352 Aug 28, 2025
CVE-2025-48362 5.4 MEDIUM EPSS 0.00
Hesabfa Accounting <2.2.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Cross Site Request Forgery. This issue affects Hesabfa Accounting: from n/a through 2.2.4.
CWE-352 Aug 28, 2025