CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
8,801 results Clear all
CVE-2025-49239 5.4 MEDIUM EPSS 0.00
Print Invoice & Delivery Notes for WooCommerce <5.5.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce allows Cross Site Request Forgery. This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 5.5.0.
CWE-352 Jun 06, 2025
CVE-2025-49238 4.3 MEDIUM EPSS 0.00
Everest Backup <2.3.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.
CWE-352 Jun 06, 2025
CVE-2025-49237 7.4 HIGH EPSS 0.00
POEditor <0.9.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor allows Path Traversal. This issue affects POEditor: from n/a through 0.9.10.
CWE-352 Jun 06, 2025
CVE-2025-30995 7.1 HIGH EPSS 0.00
OTWthemes Widgetize Pages Light -<3.0 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light allows Stored XSS. This issue affects Widgetize Pages Light: from n/a through 3.0.
CWE-352 Jun 06, 2025
CVE-2025-30994 4.3 MEDIUM EPSS 0.00
CubeWP - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Emraan Cheema CubeWP – All-in-One Dynamic Content Framework allows Cross Site Request Forgery. This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.23.
CWE-352 Jun 06, 2025
CVE-2025-30986 5.4 MEDIUM EPSS 0.00
Elite Video Player <10.0.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player allows Cross Site Request Forgery. This issue affects Elite Video Player: from n/a through 10.0.5.
CWE-352 Jun 06, 2025
CVE-2025-30981 6.3 MEDIUM EPSS 0.00
WP-Recall <16.26.14 - CSRF/Privilege Escalation
Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.
CWE-352 Jun 06, 2025
CVE-2025-30980 4.3 MEDIUM EPSS 0.00
Alessandro Piconi Simple Keyword to Link - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link allows Cross Site Request Forgery. This issue affects Simple Keyword to Link: from n/a through 1.5.
CWE-352 Jun 06, 2025
CVE-2025-30968 5.4 MEDIUM EPSS 0.00
jokerbr313 Advanced Post List <0.5.6.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List allows Cross Site Request Forgery. This issue affects Advanced Post List: from n/a through 0.5.6.2.
CWE-352 Jun 06, 2025
CVE-2025-30956 4.3 MEDIUM EPSS 0.00
Booqable Rental <2.4.20 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Booqable Rental Software Booqable Rental allows Cross Site Request Forgery. This issue affects Booqable Rental: from n/a through 2.4.20.
CWE-352 Jun 06, 2025
CVE-2025-30948 4.3 MEDIUM EPSS 0.00
Giraphix Creative Layouts for Elementor - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Giraphix Creative Layouts for Elementor allows Cross Site Request Forgery. This issue affects Layouts for Elementor: from n/a through 1.11.
CWE-352 Jun 06, 2025
CVE-2025-30946 4.3 MEDIUM EPSS 0.00
Michael Cannon Custom Bulk/Quick Edit <1.6.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit allows Cross Site Request Forgery. This issue affects Custom Bulk/Quick Edit: from n/a through 1.6.10.
CWE-352 Jun 06, 2025
CVE-2025-30632 5.4 MEDIUM EPSS 0.00
Pozzad Global Translator <2.0.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in pozzad Global Translator allows Cross Site Request Forgery. This issue affects Global Translator: from n/a through 2.0.2.
CWE-352 Jun 06, 2025
CVE-2025-30629 4.3 MEDIUM EPSS 0.00
Bitly URL Shortener <1.3.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Codehaveli Bitly URL Shortener allows Cross Site Request Forgery. This issue affects Bitly URL Shortener: from n/a through 1.3.3.
CWE-352 Jun 06, 2025
CVE-2025-29005 4.3 MEDIUM EPSS 0.00
weblizar HR Management Lite <3.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in weblizar HR Management Lite allows Cross Site Request Forgery. This issue affects HR Management Lite: from n/a through 3.3.
CWE-352 Jun 06, 2025
CVE-2025-28986 8.2 HIGH EPSS 0.00
Epicwin Plugin <1.5 - CSRF/SQL Injection
Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin allows SQL Injection. This issue affects Epicwin Plugin: from n/a through 1.5.
CWE-352 Jun 06, 2025
CVE-2025-28984 4.3 MEDIUM EPSS 0.00
WooCommerce Subscription Renewal Reminders <1.3.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce allows Cross Site Request Forgery. This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through 1.3.7.
CWE-352 Jun 06, 2025
CVE-2025-28981 7.1 HIGH EPSS 0.00
Soli WP Mail Options <0.2.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options allows Stored XSS. This issue affects WP Mail Options: from n/a through 0.2.3.
CWE-352 Jun 06, 2025
CVE-2025-28974 7.1 HIGH EPSS 0.00
mail250 Free WP Mail SMTP <1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in mail250 Free WP Mail SMTP allows Stored XSS. This issue affects Free WP Mail SMTP: from n/a through 1.0.
CWE-352 Jun 06, 2025
CVE-2025-28966 7.1 HIGH EPSS 0.00
dilemma123 Recent Posts Slider Responsive <1.0.1 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive allows Stored XSS. This issue affects Recent Posts Slider Responsive: from n/a through 1.0.1.
CWE-352 Jun 06, 2025