CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
8,801 results Clear all
CVE-2025-49399 8.8 HIGH EPSS 0.00
Basix NEX-Forms - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms allows Cross Site Request Forgery. This issue affects NEX-Forms: from n/a through 9.1.3.
CWE-352 Aug 20, 2025
CVE-2025-49391 4.3 MEDIUM EPSS 0.00
Fetch Designs Sign-up Sheets <2.3.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets allows Cross Site Request Forgery. This issue affects Sign-up Sheets: from n/a through 2.3.3.
CWE-352 Aug 20, 2025
CVE-2025-49382 8.8 HIGH EPSS 0.00
DexignZone JobZilla - Job Board WP Theme <2.0 - CSRF/PrivEsc
Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme allows Privilege Escalation. This issue affects JobZilla - Job Board WordPress Theme: from n/a through 2.0.
CWE-352 Aug 20, 2025
CVE-2025-49381 9.6 CRITICAL EPSS 0.00
ads.txt Guru <1.1.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect allows Cross Site Request Forgery. This issue affects ads.txt Guru Connect: from n/a through 1.1.1.
CWE-352 Aug 20, 2025
CVE-2025-43745 6.5 MEDIUM EPSS 0.00
Liferay Digital Experience Platform < 2024.q1.20 - CSRF
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behalf of the authenticated user via the endpoint parameter.
CWE-352 Aug 19, 2025
CVE-2025-7686 6.1 MEDIUM EPSS 0.00
WordPress weichuncai 1.5 - CSRF
The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the sm-options.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 16, 2025
CVE-2025-7684 6.1 MEDIUM EPSS 0.00
Last.fm Recent Album Artwork 1.0.2 - CSRF
The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the 'lastfm_albums_artwork.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 16, 2025
CVE-2025-7683 6.1 MEDIUM EPSS 0.00
WordPress - CSRF
The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. This is due to missing or incorrect nonce validation on the 'LatestCheckins' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 16, 2025
CVE-2025-7668 6.1 MEDIUM EPSS 0.00
Linux Promotional Plugin <1.4 - CSRF
The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'inux-promotional-plugin.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 16, 2025
CVE-2025-49895 8.8 HIGH EPSS 0.00
iThemes ServerBuddy <1.0.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com: from n/a through 1.0.5.
CWE-352 Aug 16, 2025
CVE-2025-7688 6.1 MEDIUM EPSS 0.00
WordPress Add User Meta <1.0.1 - CSRF
The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'add-user-meta' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Aug 15, 2025
CVE-2025-8992 4.3 MEDIUM 1 PoC EPSS 0.00
Mtons Mblog < 3.5.0 - Missing Authorization
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Aug 15, 2025
CVE-2025-54732 4.3 MEDIUM EPSS 0.00
Shahjada WPDM - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages allows Cross Site Request Forgery. This issue affects WPDM – Premium Packages: from n/a through 6.0.2.
CWE-352 Aug 14, 2025
CVE-2025-54728 4.3 MEDIUM EPSS 0.00
CM On Demand Search And Replace <1.5.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace allows Cross Site Request Forgery. This issue affects CM On Demand Search And Replace: from n/a through 1.5.2.
CWE-352 Aug 14, 2025
CVE-2025-53587 8.8 HIGH EPSS 0.00
ApusTheme Findgo - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery. This issue affects Findgo: from n/a through 1.3.57.
CWE-352 Aug 14, 2025
CVE-2025-53347 4.3 MEDIUM EPSS 0.00
Kalium <3.18.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.
CWE-352 Aug 14, 2025
CVE-2025-53249 6.5 MEDIUM EPSS 0.00
hakeemnala Build App Online <1.0.23 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online allows Cross Site Request Forgery. This issue affects Build App Online: from n/a through 1.0.23.
CWE-352 Aug 14, 2025
CVE-2025-53219 5.4 MEDIUM EPSS 0.00
pl4g4 WP-Database-Optimizer-Tools - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools allows Cross Site Request Forgery. This issue affects WP-Database-Optimizer-Tools: from n/a through 0.2.
CWE-352 Aug 14, 2025
CVE-2025-52797 8.2 HIGH EPSS 0.00
StoryMap <2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap allows SQL Injection. This issue affects StoryMap: from n/a through 2.1.
CWE-352 Aug 14, 2025
CVE-2025-52769 4.3 MEDIUM EPSS 0.00
flexostudio flexo-social-gallery <1.0006 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery allows Cross Site Request Forgery. This issue affects flexo-social-gallery: from n/a through 1.0006.
CWE-352 Aug 14, 2025