CVE & Exploit Intelligence Database

Updated 53m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2025-28964 7.1 HIGH EPSS 0.00
mangup Personal Favicon <2.0 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon allows Stored XSS. This issue affects Personal Favicon: from n/a through 2.0.
CWE-352 Jun 06, 2025
CVE-2025-28958 7.1 HIGH EPSS 0.00
Bg Orthodox Calendar <0.13.10 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10.
CWE-352 Jun 06, 2025
CVE-2025-28954 7.4 HIGH EPSS 0.00
wphobby Backwp <2.0.2 - CSRF/Path Traversal
Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp allows Path Traversal. This issue affects Backwp: from n/a through 2.0.2.
CWE-352 Jun 06, 2025
CVE-2025-28952 4.3 MEDIUM EPSS 0.00
Jonathan Lau CubePoints <3.2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Lau CubePoints allows Cross Site Request Forgery. This issue affects CubePoints: from n/a through 3.2.1.
CWE-352 Jun 06, 2025
CVE-2025-28950 7.1 HIGH EPSS 0.00
Post Author <1.1.1. - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author allows Stored XSS. This issue affects Post Author: from n/a through 1.1.1.
CWE-352 Jun 06, 2025
CVE-2025-28948 7.1 HIGH EPSS 0.00
Codedraft Mediabay - WordPress Media Library Folders <1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.
CWE-352 Jun 06, 2025
CVE-2025-27360 4.3 MEDIUM EPSS 0.00
WP Corner Quick Event Calendar <1.4.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Cross Site Request Forgery. This issue affects Quick Event Calendar: from n/a through 1.4.9.
CWE-352 Jun 06, 2025
CVE-2025-27359 4.3 MEDIUM EPSS 0.00
Seerox WP Media File Type Manager <2.3.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Media File Type Manager allows Cross Site Request Forgery. This issue affects WP Media File Type Manager: from n/a through 2.3.0.
CWE-352 Jun 06, 2025
CVE-2025-26593 4.3 MEDIUM EPSS 0.00
FasterThemes FastBook - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook allows Cross Site Request Forgery. This issue affects FastBook: from n/a through 1.1.
CWE-352 Jun 06, 2025
CVE-2025-24772 5.4 MEDIUM EPSS 0.00
Pay with Contact Form 7 <1.0.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in cmsMinds Pay with Contact Form 7 allows Cross Site Request Forgery. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.
CWE-352 Jun 06, 2025
CVE-2025-49077 4.3 MEDIUM EPSS 0.00
ThemeHigh Dynamic Pricing <2.2.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9.
CWE-352 Jun 06, 2025
CVE-2025-48328 4.3 MEDIUM EPSS 0.00
Daman Jeet Real Time Validation for Gravity Forms <1.7.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Daman Jeet Real Time Validation for Gravity Forms allows Cross Site Request Forgery.This issue affects Real Time Validation for Gravity Forms: from n/a through 1.7.0.
CWE-352 Jun 06, 2025
CVE-2025-5732 4.3 MEDIUM EPSS 0.00
Carmelo Traffic Offense Reporting System - Missing Authorization
A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Jun 06, 2025
CVE-2025-5019 5.4 MEDIUM EPSS 0.00
Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin...
The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the hs_update_ai_chat_settings() function. This makes it possible for unauthenticated attackers to reconfigure the plugin’s AI/chat settings (including API keys) and to potentially redirect notifications or leak data to attacker-controlled endpoints via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 06, 2025
CVE-2025-4966 6.1 MEDIUM EPSS 0.00
Hk1993 WP Online Users Stats < 1.0.0 - CSRF
The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 06, 2025
CVE-2025-2935 5.4 MEDIUM EPSS 0.00
Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms - XSS
The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for unauthenticated attackers to delete pending comments, and re-enable a previously blocked user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Jun 06, 2025
CVE-2025-36513 4.3 MEDIUM EPSS 0.00
i-PRO Co., Ltd. - CSRF
Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
CWE-352 Jun 06, 2025
CVE-2025-46257 4.3 MEDIUM EPSS 0.00
BdThemes Element Pack Pro <8.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.
CWE-352 Jun 05, 2025
CVE-2025-31482 4.3 MEDIUM EPSS 0.00
Freshrss < 1.26.2 - CSRF
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that user to suffer denial of service. Version 1.26.2 contains a patch for the issue.
CWE-352 Jun 04, 2025
CVE-2025-4580 4.3 MEDIUM EPSS 0.00
Dimdavid File Provider < 1.2.3 - CSRF
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 Jun 04, 2025