CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2025-32310 8.8 HIGH EPSS 0.00
ThemeMove QuickCal <1.0.13 - CSRF/Privilege Escalation
Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal allows Privilege Escalation. This issue affects QuickCal: from n/a through 1.0.13.
CWE-352 May 16, 2025
CVE-2025-31922 7.1 HIGH EPSS 0.00
QuanticaLabs CSS3 Accordions <3.0 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Stored XSS. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.
CWE-352 May 16, 2025
CVE-2025-31921 4.3 MEDIUM EPSS 0.00
loopus WP Ultimate Tours Builder - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder allows Cross Site Request Forgery. This issue affects WP Ultimate Tours Builder: from n/a through 1.055.
CWE-352 May 16, 2025
CVE-2025-31915 5.4 MEDIUM EPSS 0.00
Pixel WordPress Form BuilderPlugin & Autoresponder <1.0.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Cross Site Request Forgery. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.
CWE-352 May 16, 2025
CVE-2025-31639 4.3 MEDIUM EPSS 0.00
Metonon Spare - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7.
CWE-352 May 16, 2025
CVE-2025-31068 4.3 MEDIUM EPSS 0.00
Seven Stars <1.4.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4.
CWE-352 May 16, 2025
CVE-2025-2247 5.4 MEDIUM EPSS 0.00
Mantus667 Wp-pmanager < 1.2 - CSRF
The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2025-1288 6.1 MEDIUM EPSS 0.00
WOOEXIM <5.0.0 - CSRF leading to XSS
The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-9711 5.4 MEDIUM EPSS 0.00
Lukashuser Ekc Tournament Manager < 2.2.2 - CSRF
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-9709 5.4 MEDIUM EPSS 0.00
Lukashuser Ekc Tournament Manager < 2.2.2 - CSRF
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-9450 6.5 MEDIUM EPSS 0.00
Syntacticsinc Easync < 1.3.15 - CSRF
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-9233 4.3 MEDIUM EPSS 0.00
Gsplugins Logo Slider < 3.7.1 - CSRF
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-8398 4.3 MEDIUM EPSS 0.00
Simple Nav Archives <2.1.3 - CSRF
The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-8286 6.5 MEDIUM EPSS 0.00
WordPress Plugin <2.6.1 - CSRF
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks
CWE-352 May 15, 2025
CVE-2024-8245 4.3 MEDIUM EPSS 0.00
GamiPress <1.0.1 - CSRF
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-8094 6.5 MEDIUM EPSS 0.00
Ntz Antispam WP <2.0e - CSRF
The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-8090 6.1 MEDIUM EPSS 0.00
JavaScript Logic WP <0.1 - CSRF
The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-8085 6.1 MEDIUM EPSS 0.00
PeoplePond WordPress <1.1.9 - CSRF
The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-8082 4.3 MEDIUM EPSS 0.00
Widgets Reset WP <0.1 - CSRF
The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-8050 4.3 MEDIUM EPSS 0.00
Custom Author Base WP <1.1.1 - CSRF
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025