CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-6459 8.8 HIGH EPSS 0.00
Scripteo Ads Pro < 4.89 - CSRF
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.89. This is due to missing or incorrect nonce validation on the bsaCreateAdTemplate function. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jul 02, 2025
CVE-2025-34050 1 PoC Analysis EPSS 0.00
AVTECH - CSRF
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.
CWE-352 Jul 01, 2025
CVE-2025-53095 9.6 CRITICAL 1 Writeup EPSS 0.00
Lizardbyte Sunshine < 2025.628.4510 - CSRF
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended actions within the Sunshine application on behalf of that user. Specifically, since the application does OS command execution by design, this issue can be exploited to abuse the "Command Preparations" feature, enabling an attacker to inject arbitrary commands that will be executed with Administrator privileges when an application is launched. This issue has been patched in version 2025.628.4510.
CWE-352 Jul 01, 2025
CVE-2025-24289 7.5 HIGH EPSS 0.00
UCRM Client Signup Plugin <1.3.4 - CSRF/XSS
A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.
CWE-352 Jun 29, 2025
CVE-2025-6865 4.3 MEDIUM 1 Writeup EPSS 0.00
DaiCuo <1.3.13 - CSRF
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 29, 2025
CVE-2025-6864 4.3 MEDIUM 1 Writeup EPSS 0.00
SeaCMS <13.2 - CSRF
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 29, 2025
CVE-2025-5937 4.3 MEDIUM EPSS 0.00
Videowhisper Micropayments < 3.2.1 - CSRF
The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the adminOptions() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 28, 2025
CVE-2025-50370 6.5 MEDIUM EPSS 0.00
Phpgurukul Medical Card Generation System 1.0 - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or validating the origin of the request.
CWE-352 Jun 27, 2025
CVE-2025-50369 6.5 MEDIUM EPSS 0.00
PHPGurukul Medical Card Gen Sys 1.0 - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifying the origin of the request.
CWE-352 Jun 27, 2025
CVE-2025-53338 7.1 HIGH EPSS 0.00
dor re.place <0.2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in dor re.place allows Stored XSS. This issue affects re.place: from n/a through 0.2.1.
CWE-352 Jun 27, 2025
CVE-2025-53332 7.1 HIGH EPSS 0.00
ethoseo Track Everything <2.0.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything allows Stored XSS. This issue affects Track Everything: from n/a through 2.0.1.
CWE-352 Jun 27, 2025
CVE-2025-53331 7.1 HIGH EPSS 0.00
RSS Digest <1.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest allows Stored XSS. This issue affects RSS Digest: from n/a through 1.5.
CWE-352 Jun 27, 2025
CVE-2025-53329 7.1 HIGH EPSS 0.00
Społecznościowa 6 PL 2013 <2.0.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in szajenw Społecznościowa 6 PL 2013 allows Stored XSS. This issue affects Społecznościowa 6 PL 2013: from n/a through 2.0.6.
CWE-352 Jun 27, 2025
CVE-2025-53327 4.3 MEDIUM EPSS 0.00
Aioseo Multibyte Descriptions <0.0.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in rui_mashita Aioseo Multibyte Descriptions allows Cross Site Request Forgery. This issue affects Aioseo Multibyte Descriptions: from n/a through 0.0.6.
CWE-352 Jun 27, 2025
CVE-2025-53317 7.1 HIGH EPSS 0.00
AcmeeDesign WPShapere Lite -n/a-1.4 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere Lite allows Stored XSS. This issue affects WPShapere Lite: from n/a through 1.4.
CWE-352 Jun 27, 2025
CVE-2025-53315 7.1 HIGH EPSS 0.00
alanft Relocate Upload <0.24.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in alanft Relocate Upload allows Stored XSS. This issue affects Relocate Upload: from n/a through 0.24.1.
CWE-352 Jun 27, 2025
CVE-2025-53314 9.6 CRITICAL EPSS 0.00
sh1zen WP Optimizer <2.3.6 - CSRF & SQL Injection
Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer allows SQL Injection. This issue affects WP Optimizer: from n/a through 2.3.6.
CWE-352 Jun 27, 2025
CVE-2025-53313 7.1 HIGH EPSS 0.00
Twitch TV Embed Suite <2.1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in plumwd Twitch TV Embed Suite allows Stored XSS. This issue affects Twitch TV Embed Suite: from n/a through 2.1.0.
CWE-352 Jun 27, 2025
CVE-2025-53312 7.1 HIGH EPSS 0.00
Looks Awesome OnionBuzz <1.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz allows Stored XSS. This issue affects OnionBuzz: from n/a through 1.0.7.
CWE-352 Jun 27, 2025
CVE-2025-53311 7.1 HIGH EPSS 0.00
Navayan Subscribe -n/a-1.13 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Amol Nirmala Waman Navayan Subscribe allows Stored XSS. This issue affects Navayan Subscribe: from n/a through 1.13.
CWE-352 Jun 27, 2025