CVE & Exploit Intelligence Database

Updated 18m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-7202 EPSS 0.00
Elgato's Key Lights - CSRF
A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.
CWE-352 Aug 06, 2025
CVE-2025-5988 5.3 MEDIUM EPSS 0.00
Ansible aap-gateway - CSRF
A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
CWE-352 Aug 04, 2025
CVE-2025-8505 4.3 MEDIUM 1 Writeup EPSS 0.00
wx-shop <de1b66331368695779cfc6e4d11a64caddf8716e - CSRF
A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CWE-862 Aug 03, 2025
CVE-2025-54782 8.8 HIGH EXPLOITED 5 PoCs 2 Writeups Analysis NUCLEI EPSS 0.24
Nestjs Devtools-integration < 0.2.1 - Command Injection
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. This is fixed in version 0.2.1.
CWE-78 Aug 02, 2025
CVE-2025-50847 6.5 MEDIUM 1 Writeup EPSS 0.00
CS Cart 4.18.3 - CSRF
Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.
CWE-352 Jul 31, 2025
CVE-2025-8335 4.3 MEDIUM EPSS 0.00
Code-projects Simple Car Rental System - Missing Authorization
A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jul 30, 2025
CVE-2025-54536 5.4 MEDIUM EPSS 0.00
Jetbrains Teamcity < 2025.07 - CSRF
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CWE-352 Jul 28, 2025
CVE-2025-54529 3.7 LOW EPSS 0.00
Jetbrains Teamcity < 2025.07 - CSRF
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CWE-352 Jul 28, 2025
CVE-2025-54528 5.4 MEDIUM EPSS 0.00
Jetbrains Teamcity < 2025.07 - CSRF
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
CWE-352 Jul 28, 2025
CVE-2025-8223 4.3 MEDIUM 1 Writeup EPSS 0.00
Jerryshensjf Jpacookieshop - Missing Authorization
A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. This affects an unknown part of the file AdminTypeCustController.java. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
CWE-862 Jul 27, 2025
CVE-2025-8104 4.3 MEDIUM EPSS 0.00
WordPress <3.98 - CSRF
The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.98. This is due to missing nonce validation in the wpmemory_install_plugin() function. This makes it possible for unauthenticated attackers to silently install one of the several whitelisted plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 27, 2025
CVE-2025-8103 4.3 MEDIUM EPSS 0.00
WPeMatico RSS Feed Fetcher <2.8.7 - CSRF
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for unauthenticated attackers to deactivate the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 26, 2025
CVE-2025-36728 6.3 MEDIUM EPSS 0.00
Simple-help Simplehelp < 5.5.11 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
CWE-352 Jul 25, 2025
CVE-2025-7835 4.3 MEDIUM EPSS 0.00
iThoughts Advanced Code Editor <1.2.10 - CSRF
The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 24, 2025
CVE-2025-7690 6.1 MEDIUM EPSS 0.00
WordPress Affiliate Plus <1.3.2 - CSRF
The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'affiplus_settings' page. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 24, 2025
CVE-2025-6214 6.5 MEDIUM EPSS 0.00
Omnishop WordPress <1.0.9 - CSRF
The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The route’s permission_callback only verifies that the requester is logged in, but fails to require any nonce or other proof of intent. This makes it possible for unauthenticated attackers to delete arbitrary user accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 23, 2025
CVE-2025-6054 6.1 MEDIUM EPSS 0.00
YANewsflash <1.0.3 - CSRF
The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'yanewsflash/yanewsflash.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 23, 2025
CVE-2025-7687 6.1 MEDIUM EPSS 0.00
WordPress Latest Post Accordian Slider <1.3 - CSRF
The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the 'lpaccordian' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 22, 2025
CVE-2025-7685 6.1 MEDIUM EPSS 0.00
Like & Share My Site <0.2 - CSRF
The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the 'lsms_admin' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 22, 2025
CVE-2025-7369 6.1 MEDIUM EPSS 0.00
WP Shortcodes Plugin - CSRF
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.
CWE-352 Jul 21, 2025