CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
8,801 results Clear all
CVE-2025-48359 7.1 HIGH EPSS 0.00
ATT YouTube Widget - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in thaihavnn07 ATT YouTube Widget allows Stored XSS. This issue affects ATT YouTube Widget: from n/a through 1.0.
CWE-352 Aug 28, 2025
CVE-2025-48357 5.4 MEDIUM EPSS 0.00
Century ToolKit - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Theme Century Century ToolKit allows Cross Site Request Forgery. This issue affects Century ToolKit: from n/a through 1.2.1.
CWE-352 Aug 28, 2025
CVE-2025-48353 7.1 HIGH EPSS 0.00
dactum Clickbank WordPress Plugin - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) allows Stored XSS. This issue affects Clickbank WordPress Plugin (Niche Storefront): from n/a through 1.3.5.
CWE-352 Aug 28, 2025
CVE-2025-48351 7.1 HIGH EPSS 0.00
PluginsPoint Kento Splash Screen -<1.4 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS. This issue affects Kento Splash Screen: from n/a through 1.4.
CWE-352 Aug 28, 2025
CVE-2025-48343 7.1 HIGH EPSS 0.00
WPMU Ldap Auth <5.0.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication allows Stored XSS. This issue affects WPMU Ldap Authentication: from n/a through 5.0.1.
CWE-352 Aug 28, 2025
CVE-2025-48325 7.1 HIGH EPSS 0.00
WP Admin Theme <1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in shmish111 WP Admin Theme allows Stored XSS. This issue affects WP Admin Theme: from n/a through 1.0.
CWE-352 Aug 28, 2025
CVE-2025-48321 7.1 HIGH EPSS 0.00
dyiosah Ultimate Twitter Profile Widget - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0.
CWE-352 Aug 28, 2025
CVE-2025-48320 7.1 HIGH EPSS 0.00
CuckooHello <1.0.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 allows Stored XSS. This issue affects 百度分享按钮: from n/a through 1.0.6.
CWE-352 Aug 28, 2025
CVE-2025-48318 4.3 MEDIUM EPSS 0.00
Duoshuo 1.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in shen2 多说社会化评论框 allows Cross Site Request Forgery. This issue affects 多说社会化评论框: from n/a through 1.2.
CWE-352 Aug 28, 2025
CVE-2025-48311 7.1 HIGH EPSS 0.00
OffClicks Invisible Optin -<1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in OffClicks Invisible Optin allows Stored XSS. This issue affects Invisible Optin: from n/a through 1.0.
CWE-352 Aug 28, 2025
CVE-2025-48310 4.3 MEDIUM EPSS 0.00
wptableeditor <1.6.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor allows Cross Site Request Forgery. This issue affects Table Editor: from n/a through 1.6.4.
CWE-352 Aug 28, 2025
CVE-2025-48309 7.1 HIGH EPSS 0.00
BetPress <1.0.1 Lite - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in web-able BetPress allows Stored XSS. This issue affects BetPress: from n/a through 1.0.1 Lite.
CWE-352 Aug 28, 2025
CVE-2025-48308 7.1 HIGH EPSS 0.00
Newsletter subscription optin <1.2.9 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module allows Stored XSS. This issue affects Newsletter subscription optin module: from n/a through 1.2.9.
CWE-352 Aug 28, 2025
CVE-2025-48307 7.1 HIGH EPSS 0.00
kasonzhao SEO For Images <1.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images allows Stored XSS. This issue affects SEO For Images: from n/a through 1.0.0.
CWE-352 Aug 28, 2025
CVE-2025-48306 7.1 HIGH EPSS 0.00
Savyour Affiliate Partner <2.1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner allows Stored XSS. This issue affects Savyour Affiliate Partner: from n/a through 2.1.4.
CWE-352 Aug 28, 2025
CVE-2025-48304 7.1 HIGH EPSS 0.00
Gary Illyes Google XML News Sitemap <0.02 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin allows Stored XSS. This issue affects Google XML News Sitemap plugin: from n/a through 0.02.
CWE-352 Aug 28, 2025
CVE-2025-48109 7.1 HIGH EPSS 0.00
Xavier Media XM-Backup <0.9.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup allows Stored XSS. This issue affects XM-Backup: from n/a through 0.9.1.
CWE-352 Aug 28, 2025
CVE-2025-54541 4.3 MEDIUM EPSS 0.00
Opensolution Quick.cms - CSRF
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CWE-352 Aug 28, 2025
CVE-2025-7812 8.8 HIGH EPSS 0.00
Video Share VOD - WordPress <2.7.6 - CSRF
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attackers to update settings and execute remote code when the Server command execution setting is enabled via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 28, 2025
CVE-2025-58217 7.1 HIGH EPSS 0.00
GeroNikolov Instant Breaking News - XSS
Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News allows Stored XSS. This issue affects Instant Breaking News: from n/a through 1.0.
CWE-352 Aug 27, 2025