CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
8,801 results Clear all
CVE-2025-58202 4.3 MEDIUM EPSS 0.00
Simple Page Access Restriction <1.0.32 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction allows Cross Site Request Forgery. This issue affects Simple Page Access Restriction: from n/a through 1.0.32.
CWE-352 Aug 27, 2025
CVE-2025-54598 6.5 MEDIUM 1 Writeup EPSS 0.00
Bevy < 2025-06-24 - CSRF
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.
CWE-352 Aug 27, 2025
CVE-2025-49040 4.3 MEDIUM EPSS 0.00
Backup Bolt - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through 1.4.1.
CWE-352 Aug 27, 2025
CVE-2025-48303 4.3 MEDIUM EPSS 0.00
Post Type Converter <0.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Kevin Langley Jr. Post Type Converter allows Cross-Site Request Forgery.This issue affects Post Type Converter: from n/a through 0.6.
CWE-352 Aug 25, 2025
CVE-2025-7842 4.3 MEDIUM EPSS 0.00
Silencesoft RSS Reader <0.6 - CSRF
The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.6. This is due to missing or incorrect nonce validation on the 'sil_rss_edit_page' page. This makes it possible for unauthenticated attackers to delete RSS feeds via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 23, 2025
CVE-2025-7841 4.3 MEDIUM EPSS 0.00
Sertifier Certificate & Badge Maker - WordPress - CSRF
The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to update the plugin's api key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 23, 2025
CVE-2025-7839 4.3 MEDIUM EPSS 0.00
WordPress <1.0 - CSRF
The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the rp_dpo_dpa_ajax_dp_delete_data() function. This makes it possible for unauthenticated attackers to delete data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 23, 2025
CVE-2025-57895 4.3 MEDIUM EPSS 0.00
JobWP <2.4.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP allows Cross Site Request Forgery. This issue affects JobWP: from n/a through 2.4.3.
CWE-352 Aug 22, 2025
CVE-2025-57893 4.3 MEDIUM EPSS 0.00
Epsiloncool WP Fast Total Search - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search allows Cross Site Request Forgery. This issue affects WP Fast Total Search: from n/a through 1.79.270.
CWE-352 Aug 22, 2025
CVE-2025-57892 4.3 MEDIUM EPSS 0.00
Jeff Starr Simple Statistics for Feeds <20250322 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds allows Cross Site Request Forgery. This issue affects Simple Statistics for Feeds: from n/a through 20250322.
CWE-352 Aug 22, 2025
CVE-2025-57885 4.3 MEDIUM EPSS 0.00
Shahjahan Jewel Fluent Support <1.9.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support allows Cross Site Request Forgery. This issue affects Fluent Support: from n/a through 1.9.1.
CWE-352 Aug 22, 2025
CVE-2025-55744 4.3 MEDIUM EPSS 0.00
UnoPim <0.2.1 - CSRF
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.
CWE-352 Aug 21, 2025
CVE-2025-8592 8.1 HIGH EPSS 0.00
Inspiro theme <2.1.2 - CSRF
The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 21, 2025
CVE-2025-50902 8.8 HIGH 1 PoC EPSS 0.00
old-peanut Open-Shop <1.0.0 - CSRF
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.
CWE-352 Aug 20, 2025
CVE-2025-43748 6.8 MEDIUM EPSS 0.00
Liferay Digital Experience Platform < 7.4 - CSRF
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attackers to execute Cross-Site Request Forgery
CWE-352 Aug 20, 2025
CVE-2025-54174 4.3 MEDIUM EPSS 0.00
Opensolution Quick.cms - CSRF
QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content defined by the attacker. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CWE-352 Aug 20, 2025
CVE-2025-8102 5.4 MEDIUM EPSS 0.00
Easy Digital Downloads <3.5.0 - CSRF
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attackers to deactivate or download and activate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 20, 2025
CVE-2025-54052 7.5 HIGH EPSS 0.00
Realtyna Organic IDX <5.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin allows PHP Local File Inclusion. This issue affects Realtyna Organic IDX plugin: from n/a through 5.0.0.
CWE-352 Aug 20, 2025
CVE-2025-49896 4.3 MEDIUM EPSS 0.00
WP Discord Post Plus - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus &#8211; Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus &#8211; Supports Unlimited Channels: from n/a through 1.0.2.
CWE-352 Aug 20, 2025
CVE-2025-49426 4.3 MEDIUM EPSS 0.00
Dourou Cookie Warning <1.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Dourou Cookie Warning allows Cross Site Request Forgery. This issue affects Cookie Warning: from n/a through 1.3.
CWE-352 Aug 20, 2025