CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-53193 4.3 MEDIUM EPSS 0.00
Burst Statistics <2.0.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics allows Cross Site Request Forgery. This issue affects Burst Statistics: from n/a through 2.0.6.
CWE-352 Jun 27, 2025
CVE-2025-5936 4.3 MEDIUM EPSS 0.00
VR Calendar < 2.4.7 - CSRF
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 27, 2025
CVE-2025-48921 8.8 HIGH EPSS 0.00
Drupal Open Social <12.3.14-12.4.13 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 before 12.4.13.
CWE-352 Jun 26, 2025
CVE-2025-48497 4.3 MEDIUM EPSS 0.00
iroha Board <v0.10.12 - CSRF
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.
CWE-352 Jun 26, 2025
CVE-2025-5932 4.3 MEDIUM EPSS 0.00
Coolrunner Homerunner < 1.0.29 - CSRF
The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.29. This is due to missing or incorrect nonce validation on the main_settings() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 26, 2025
CVE-2025-6664 4.3 MEDIUM 1 Writeup EPSS 0.00
Codeastro Patient Record Management System - Missing Authorization
A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 25, 2025
CVE-2025-50179 4.6 MEDIUM 1 Writeup EPSS 0.00
Tuleap <16.8.99.1749830289, <16.9-1 - CSRF
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition prior to version 16.9-1 to trick victims into changing the canned responses. Tuleap Community Edition 16.8.99.1749830289 and Tuleap Enterprise Edition 16.9-1 contain a patch for the issue.
CWE-352 Jun 25, 2025
CVE-2025-48991 4.6 MEDIUM 1 Writeup EPSS 0.00
Tuleap <16.8.99.1748845907 - SSRF
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned responses. Tuleap Community Edition 16.8.99.1748845907, Tuleap Enterprise Edition 16.8-3, and Tuleap Enterprise Edition 16.7-5 contain a fix for the vulnerability.
CWE-352 Jun 25, 2025
CVE-2025-6478 4.3 MEDIUM EPSS 0.00
Codeastro Expense Management System - Missing Authorization
A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely.
CWE-862 Jun 22, 2025
CVE-2025-6476 4.3 MEDIUM EPSS 0.00
Oretnom23 Gym Management System - Missing Authorization
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 22, 2025
CVE-2024-4994 8.1 HIGH EPSS 0.00
GitLab CE/EE <16.11.5 & <17.0.3 & <17.1.1 - CSRF
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.
CWE-352 Jun 20, 2025
CVE-2025-52825 8.8 HIGH EPSS 0.00
Rameez Iqbal Real Estate Manager - CSRF/Privilege Escalation
Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager allows Privilege Escalation. This issue affects Real Estate Manager: from n/a through 7.3.
CWE-352 Jun 20, 2025
CVE-2025-52795 7.1 HIGH EPSS 0.00
WP Front User Submit/Front Editor <4.9.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor allows Cross Site Request Forgery. This issue affects WP Front User Submit / Front Editor: from n/a through 4.9.4.
CWE-352 Jun 20, 2025
CVE-2025-52794 7.1 HIGH EPSS 0.00
Creative Contact Form <1.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form allows Stored XSS. This issue affects Creative Contact Form: from n/a through 1.0.0.
CWE-352 Jun 20, 2025
CVE-2025-52793 7.1 HIGH EPSS 0.00
Esselink.nu Settings <2.94 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Esselink.nu Esselink.nu Settings allows Reflected XSS. This issue affects Esselink.nu Settings: from n/a through 2.94.
CWE-352 Jun 20, 2025
CVE-2025-52792 7.1 HIGH EPSS 0.00
vgstef WP User Stylesheet Switcher <v2.2.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher allows Stored XSS. This issue affects WP User Stylesheet Switcher: from n/a through v2.2.0.
CWE-352 Jun 20, 2025
CVE-2025-52791 7.1 HIGH EPSS 0.00
devfelixmoira Knowledge Base <1.1.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker allows Stored XSS. This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through 1.1.8.
CWE-352 Jun 20, 2025
CVE-2025-52790 7.1 HIGH EPSS 0.00
r-win WP-DownloadCounter - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter allows Stored XSS. This issue affects WP-DownloadCounter: from n/a through 1.01.
CWE-352 Jun 20, 2025
CVE-2025-52789 7.1 HIGH EPSS 0.00
Lewe ChordPress <3.9.7 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress allows Stored XSS. This issue affects Lewe ChordPress: from n/a through 3.9.7.
CWE-352 Jun 20, 2025
CVE-2025-52784 7.1 HIGH EPSS 0.00
hideoguchi Bluff Post - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in hideoguchi Bluff Post allows Stored XSS. This issue affects Bluff Post: from n/a through 1.1.1.
CWE-352 Jun 20, 2025