CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-48111 4.3 MEDIUM EPSS 0.00
YITH PayPal Express Checkout <1.49.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0.
CWE-352 Jun 17, 2025
CVE-2025-6106 4.3 MEDIUM EPSS 0.00
72crm Wukong Crm - Missing Authorization
A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unknown processing of the file AdminRoleController.java. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-862 Jun 16, 2025
CVE-2025-6105 4.3 MEDIUM EPSS 0.00
Jflyfox Jfinal Cms - Missing Authorization
A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of the argument Logout leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-862 Jun 16, 2025
CVE-2025-6064 6.1 MEDIUM EPSS 0.00
WP URL Shortener <1.2 - CSRF
The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-6063 6.1 MEDIUM EPSS 0.00
XiSearch bar plugin <2.6 - CSRF
The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-6062 4.3 MEDIUM EPSS 0.00
Yougler Blogger Profile Page <1.01 - CSRF
The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-6055 6.1 MEDIUM EPSS 0.00
Zen Sticky Social 0.3 - CSRF
The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-4592 4.3 MEDIUM EPSS 0.00
AI Image Lab Free AI Image Generator <1.0.6 - CSRF
The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the 'wpz-ai-images' page. This makes it possible for unauthenticated attackers to update the plugin's API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-6059 4.3 MEDIUM EPSS 0.00
Seraphinite Accelerator <2.27.21 - CSRF
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several administrative actions, including deleting the cache, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 14, 2025
CVE-2025-5938 5.3 MEDIUM EPSS 0.00
Themebon Digital Marketing And Agency... - CSRF
The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthenticated attackers to trigger an import via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 13, 2025
CVE-2025-5930 4.3 MEDIUM EPSS 0.00
WP2HTML <1.0.2 - CSRF
The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 13, 2025
CVE-2025-5928 4.3 MEDIUM EPSS 0.00
WP Sliding Login/Dashboard Panel <2.1.1 - CSRF
The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the wp_sliding_panel_user_options() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 13, 2025
CVE-2025-5926 6.1 MEDIUM EPSS 0.00
Link Shield <0.5.4 - CSRF
The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing or incorrect nonce validation on the link_shield_menu_options() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 13, 2025
CVE-2025-6001 8.3 HIGH EPSS 0.00
VirtueMart - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.
CWE-352 Jun 11, 2025
CVE-2025-41661 8.8 HIGH EPSS 0.00
Unknown Device - CSRF
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.
CWE-352 Jun 11, 2025
CVE-2025-36576 2.7 LOW EPSS 0.00
Dell Wyse Management Suite < 5.2 - CSRF
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
CWE-352 Jun 10, 2025
CVE-2025-49511 7.1 HIGH EPSS 0.00
uxper Civi Framework - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
CWE-352 Jun 10, 2025
CVE-2025-49510 4.3 MEDIUM EPSS 0.00
WPFactory Min Max Step Quantity Limits Manager for WooCommerce - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce allows Cross Site Request Forgery.This issue affects Min Max Step Quantity Limits Manager for WooCommerce: from n/a through 5.1.0.
CWE-352 Jun 10, 2025
CVE-2025-5925 4.3 MEDIUM EPSS 0.00
Bunny's Print CSS <0.95 - CSRF
The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to missing or incorrect nonce validation on the pcss_options_subpanel() function. This makes it possible for unauthenticated attackers to update settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 10, 2025
CVE-2025-5900 4.3 MEDIUM EPSS 0.00
Tenda Ac9 Firmware - Missing Authorization
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 09, 2025