CVE & Exploit Intelligence Database

Updated 18m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-7834 4.3 MEDIUM EPSS 0.00
PHPGurukul Complaint Management System 2.0 - CSRF
A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jul 19, 2025
CVE-2025-7669 6.1 MEDIUM EPSS 0.00
Avishi WP PayPal Payment Button <2.0 - CSRF
The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the 'avishi-wp-paypal-payment-button/index.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 19, 2025
CVE-2025-50586 6.5 MEDIUM EPSS 0.00
StudentManage v1.0 - CSRF
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
CWE-352 Jul 18, 2025
CVE-2025-6781 4.3 MEDIUM EPSS 0.00
Copymatic - AI Content Writer & Generator <2.1 - CSRF
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update the copymatic_apikey option via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 18, 2025
CVE-2025-6053 6.1 MEDIUM EPSS 0.00
Zuppler Online Ordering <2.1.0 - CSRF
The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 18, 2025
CVE-2025-7756 4.3 MEDIUM EPSS 0.00
code-projects E-Commerce Site 1.0 - CSRF
A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jul 17, 2025
CVE-2025-54042 4.3 MEDIUM EPSS 0.00
xfinitysoft WP Post Hide <1.0.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in xfinitysoft WP Post Hide allows Cross Site Request Forgery. This issue affects WP Post Hide: from n/a through 1.0.9.
CWE-352 Jul 16, 2025
CVE-2025-54041 4.3 MEDIUM EPSS 0.00
WP Swings Wallet System for WooCommerce <2.6.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce allows Cross Site Request Forgery. This issue affects Wallet System for WooCommerce: from n/a through 2.6.7.
CWE-352 Jul 16, 2025
CVE-2025-54039 4.3 MEDIUM EPSS 0.00
Toast Plugins Animator <3.0.16 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator allows Cross Site Request Forgery. This issue affects Animator: from n/a through 3.0.16.
CWE-352 Jul 16, 2025
CVE-2025-54038 5.4 MEDIUM EPSS 0.00
MotoPress Restaurant Menu <2.4.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress allows Cross Site Request Forgery. This issue affects Restaurant Menu by MotoPress: from n/a through 2.4.6.
CWE-352 Jul 16, 2025
CVE-2025-54036 4.3 MEDIUM EPSS 0.00
Webba Booking <5.1.20 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking allows Cross Site Request Forgery. This issue affects Webba Booking: from n/a through 5.1.20.
CWE-352 Jul 16, 2025
CVE-2025-54035 4.3 MEDIUM EPSS 0.00
Tribulant Software Newsletters <4.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters allows Cross Site Request Forgery. This issue affects Newsletters: from n/a through 4.10.
CWE-352 Jul 16, 2025
CVE-2025-54033 6.5 MEDIUM EPSS 0.00
BlocksWP Theme Builder For Elementor <1.2.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor allows Cross Site Request Forgery. This issue affects Theme Builder For Elementor: from n/a through 1.2.3.
CWE-352 Jul 16, 2025
CVE-2025-54030 4.3 MEDIUM EPSS 0.00
WooCommerce Google Sheet Connector <1.3.20 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in GSheetConnector by WesternDeal WooCommerce Google Sheet Connector allows Cross Site Request Forgery. This issue affects WooCommerce Google Sheet Connector: from n/a through 1.3.20.
CWE-352 Jul 16, 2025
CVE-2025-54022 6.5 MEDIUM EPSS 0.00
RelyWP Coupon Affiliates <6.4.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates allows Cross Site Request Forgery. This issue affects Coupon Affiliates: from n/a through 6.4.0.
CWE-352 Jul 16, 2025
CVE-2025-54020 5.4 MEDIUM EPSS 0.00
Erik AntiSpam for Contact Form 7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 allows Cross Site Request Forgery. This issue affects AntiSpam for Contact Form 7: from n/a through 0.6.3.
CWE-352 Jul 16, 2025
CVE-2025-54010 9.6 CRITICAL EPSS 0.00
Shahjahan Jewel FluentSnippets <10.50 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets allows Cross Site Request Forgery. This issue affects FluentSnippets: from n/a through 10.50.
CWE-352 Jul 16, 2025
CVE-2025-48153 7.1 HIGH EPSS 0.00
Atakan Au Import CDN-Remote Images <2.1.2 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS. This issue affects Import CDN-Remote Images: from n/a through 2.1.2.
CWE-352 Jul 16, 2025
CVE-2025-50090 5.4 MEDIUM EPSS 0.00
Oracle E-Business Suite - Personalization - Info Disclosure
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
CWE-352 Jul 15, 2025
CVE-2025-30756 6.1 MEDIUM EPSS 0.00
Oracle Rest Data Services - CSRF
Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data as well as unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CWE-352 Jul 15, 2025