CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-5888 4.3 MEDIUM EPSS 0.00
Jsnjfz Webstack-guns - Missing Authorization
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-862 Jun 09, 2025
CVE-2025-5885 4.3 MEDIUM EPSS 0.00
Konicaminolta Bizhub < 2025-02-02 - Missing Authorization
A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 09, 2025
CVE-2025-5766 4.3 MEDIUM EPSS 0.00
Code-projects Simple Laundry System - Missing Authorization
A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 06, 2025
CVE-2025-49453 7.1 HIGH EPSS 0.00
Jatinder Pal Singh BP Profile <1.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage allows Stored XSS. This issue affects BP Profile as Homepage: from n/a through 1.1.
CWE-352 Jun 06, 2025
CVE-2025-49449 4.3 MEDIUM EPSS 0.00
WP Map Plugins Interactive Regional Map of Africa - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa allows Cross Site Request Forgery. This issue affects Interactive Regional Map of Africa: from n/a through 1.0.
CWE-352 Jun 06, 2025
CVE-2025-49446 4.3 MEDIUM EPSS 0.00
minhlaobao Admin Notes <1.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.
CWE-352 Jun 06, 2025
CVE-2025-49445 4.3 MEDIUM EPSS 0.00
WP Map Plugins Interactive UK Regional Map - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map allows Cross Site Request Forgery. This issue affects Interactive UK Regional Map: from n/a through 2.0.
CWE-352 Jun 06, 2025
CVE-2025-49440 4.3 MEDIUM EPSS 0.00
WP Security Master <1.0.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master allows Cross Site Request Forgery. This issue affects WP Security Master: from n/a through 1.0.2.
CWE-352 Jun 06, 2025
CVE-2025-49439 4.3 MEDIUM EPSS 0.00
mariusz88atelierweb Atelier Create CV <1.1.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV allows Cross Site Request Forgery. This issue affects Atelier Create CV: from n/a through 1.1.2.
CWE-352 Jun 06, 2025
CVE-2025-49435 4.3 MEDIUM EPSS 0.00
Hasina77 Wp Easy Allopass - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass allows Cross Site Request Forgery. This issue affects Wp Easy Allopass: from n/a through 4.1.1.
CWE-352 Jun 06, 2025
CVE-2025-49425 7.1 HIGH EPSS 0.00
Konami Easter Egg <v0.4 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg allows Stored XSS. This issue affects Konami Easter Egg: from n/a through v0.4.
CWE-352 Jun 06, 2025
CVE-2025-49332 4.3 MEDIUM EPSS 0.00
WP Time Slots Booking Form <1.2.30 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form allows Cross Site Request Forgery. This issue affects WP Time Slots Booking Form: from n/a through 1.2.30.
CWE-352 Jun 06, 2025
CVE-2025-49317 4.3 MEDIUM EPSS 0.00
NTC WP Page Loading <1.0.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading allows Cross Site Request Forgery. This issue affects WP Page Loading: from n/a through 1.0.6.
CWE-352 Jun 06, 2025
CVE-2025-49291 4.3 MEDIUM EPSS 0.00
Codepeople Calculated Fields Form < 5.3.59 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.
CWE-352 Jun 06, 2025
CVE-2025-49286 4.3 MEDIUM EPSS 0.00
WP Table Builder <2.0.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder allows Cross Site Request Forgery. This issue affects WP Table Builder: from n/a through 2.0.6.
CWE-352 Jun 06, 2025
CVE-2025-49285 4.3 MEDIUM EPSS 0.00
WP Cookie Notice <3.8.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Cross Site Request Forgery. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 3.8.0.
CWE-352 Jun 06, 2025
CVE-2025-49284 4.3 MEDIUM EPSS 0.00
WP Maintenance Mode & Site Under Construction <4.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction allows Cross Site Request Forgery. This issue affects WP Maintenance Mode & Site Under Construction: from n/a through 4.3.
CWE-352 Jun 06, 2025
CVE-2025-49283 4.3 MEDIUM EPSS 0.00
Matthias Nordwig - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant allows Cross Site Request Forgery. This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through 4.1.1.
CWE-352 Jun 06, 2025
CVE-2025-49273 4.3 MEDIUM EPSS 0.00
Bill Minozzi WP Tools <5.24 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site Request Forgery. This issue affects WP Tools: from n/a through 5.24.
CWE-352 Jun 06, 2025
CVE-2025-49269 4.3 MEDIUM EPSS 0.00
Anton Vanyukov Market Exporter <2.0.22 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter allows Cross Site Request Forgery. This issue affects Market Exporter: from n/a through 2.0.22.
CWE-352 Jun 06, 2025