CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2025-39351 4.3 MEDIUM EPSS 0.00
Themegoods Grand Restaurant < 7.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
CWE-352 May 19, 2025
CVE-2025-48344 5.4 MEDIUM EPSS 0.00
Rootspersona <3.7.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona allows Cross Site Request Forgery. This issue affects Rootspersona: from n/a through 3.7.5.
CWE-352 May 19, 2025
CVE-2025-48342 5.4 MEDIUM EPSS 0.00
RedefiningTheWeb Dynamic Pricing & Discounts Lite - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing &amp; Discounts Lite for WooCommerce allows Cross Site Request Forgery. This issue affects Dynamic Pricing &amp; Discounts Lite for WooCommerce: from n/a through 2.0.3.
CWE-352 May 19, 2025
CVE-2025-48285 4.3 MEDIUM EPSS 0.00
sbouey Falang multilanguage <1.3.61 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage allows Cross Site Request Forgery. This issue affects Falang multilanguage: from n/a through 1.3.61.
CWE-352 May 19, 2025
CVE-2025-48284 5.4 MEDIUM EPSS 0.00
Japanized For WooCommerce <2.6.40 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce allows Cross Site Request Forgery. This issue affects Japanized For WooCommerce: from n/a through 2.6.40.
CWE-352 May 19, 2025
CVE-2025-48265 4.3 MEDIUM EPSS 0.00
Pektsekye Year Make Model Search for WooCommerce <1.0.11 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Pektsekye Year Make Model Search for WooCommerce allows Cross Site Request Forgery. This issue affects Year Make Model Search for WooCommerce: from n/a through 1.0.11.
CWE-352 May 19, 2025
CVE-2025-48264 4.3 MEDIUM EPSS 0.00
Product Code for WooCommerce <1.5.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in artiosmedia Product Code for WooCommerce allows Cross Site Request Forgery. This issue affects Product Code for WooCommerce: from n/a through 1.5.0.
CWE-352 May 19, 2025
CVE-2025-48259 4.3 MEDIUM EPSS 0.00
WP Mapa Politico España <3.8.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España allows Cross Site Request Forgery. This issue affects WP Mapa Politico España: from n/a through 3.8.0.
CWE-352 May 19, 2025
CVE-2025-48255 4.3 MEDIUM EPSS 0.00
Videowhisper Live Streaming Integration < 6.2.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP allows Cross Site Request Forgery. This issue affects Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: from n/a through 6.2.4.
CWE-352 May 19, 2025
CVE-2025-48243 4.3 MEDIUM EPSS 0.00
reCAPTCHA <2.26 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26.
CWE-352 May 19, 2025
CVE-2025-48238 7.1 HIGH EPSS 0.00
AWcode Toolkit <1.0.18 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit allows Stored XSS. This issue affects AWcode Toolkit: from n/a through 1.0.18.
CWE-352 May 19, 2025
CVE-2025-48233 7.1 HIGH EPSS 0.00
Affiliates Manager Google reCAPTCHA Integration <1.0.6 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration allows Stored XSS. This issue affects Affiliates Manager Google reCAPTCHA Integration: from n/a through 1.0.6.
CWE-352 May 19, 2025
CVE-2025-4887 4.3 MEDIUM 1 Writeup EPSS 0.00
Senior-walter Online Student Clearance System - Missing Authorization
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-862 May 18, 2025
CVE-2025-4194 6.1 MEDIUM EPSS 0.00
WordPress AlT Monitoring <1.0.3 - CSRF
The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 17, 2025
CVE-2025-4189 6.1 MEDIUM EPSS 0.00
Audio Comments Plugin <1.0.4 - CSRF
The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the 'audio-comments/audior-settings.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 17, 2025
CVE-2022-4363 6.5 MEDIUM EPSS 0.00
Wholesale Market <2.2.2 & Wholesale Market for WooCommerce <2.0.1 -...
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
CWE-352 May 16, 2025
CVE-2025-48146 7.1 HIGH EPSS 0.00
Lupsonline Seo Flow < 2.2.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline allows Stored XSS. This issue affects SEO Flow by LupsOnline: from n/a through 2.2.0.
CWE-352 May 16, 2025
CVE-2025-48144 7.1 HIGH EPSS 0.00
Sidngr Import Export For Woocommerce < 1.6.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2.
CWE-352 May 16, 2025
CVE-2025-48115 4.3 MEDIUM EPSS 0.00
Javier Revilla ValidateCertify <1.6.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.2.
CWE-352 May 16, 2025
CVE-2025-48114 7.1 HIGH EPSS 0.00
ShayanWeb Admin FontChanger -n/a-1.9.1 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in ShayanWeb Admin FontChanger allows Stored XSS.This issue affects ShayanWeb Admin FontChanger: from n/a through 1.9.1.
CWE-352 May 16, 2025