CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2025-47886 4.3 MEDIUM EPSS 0.00
Jenkins Cadence Vmanager - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
CWE-352 May 14, 2025
CVE-2025-47708 8.8 HIGH EPSS 0.00
Miniorange 2fa < 5.2.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
CWE-352 May 14, 2025
CVE-2025-47701 8.8 HIGH EPSS 0.00
Restrict Route BY IP < 1.3.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.
CWE-352 May 14, 2025
CVE-2025-44186 5.4 MEDIUM 1 Writeup EPSS 0.00
Mayurik Best Employee Management System - CSRF
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.
CWE-352 May 14, 2025
CVE-2025-47204 6.1 MEDIUM EXPLOITED 1 Writeup NUCLEI EPSS 0.01
Davidstutz Bootstrap Multiselect - CSRF
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).
CWE-352 May 13, 2025
CVE-2025-46721 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
nosurf <1.2.0 - CSRF
nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the target site, or on a subdomain of the target site (either via XSS, or otherwise) to bypass CSRF checks and issue requests on user's behalf. Due to misuse of the Go `net/http` library, nosurf categorizes all incoming requests as plain-text HTTP requests, in which case the `Referer` header is not checked to have the same origin as the target webpage. If the attacker has control over HTML contents on either the target website (e.g. `example.com`), or on a website hosted on a subdomain of the target (e.g. `attacker.example.com`), they will also be able to manipulate cookies set for the target website. By acquiring the secret CSRF token from the cookie, or overriding the cookie with a new token known to the attacker, `attacker.example.com` is able to craft cross-site requests to `example.com`. A patch for the issue was released in nosurf 1.2.0. In lieu of upgrading to a patched version of nosurf, users may additionally use another HTTP middleware to ensure that a non-safe HTTP request is coming from the same origin (e.g. by requiring a `Sec-Fetch-Site: same-origin` header in the request).
CWE-352 May 13, 2025
CVE-2025-31205 6.5 MEDIUM EPSS 0.00
Apple Safari < 18.5 - CSRF
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.
CWE-352 May 12, 2025
CVE-2025-24223 8.0 HIGH EPSS 0.00
Apple Safari < 18.5 - CSRF
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.
CWE-352 May 12, 2025
CVE-2025-46743 6.3 MEDIUM EPSS 0.00
Token Expired - Info Disclosure
An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.
CWE-352 May 12, 2025
CVE-2025-46610 8.8 HIGH EPSS 0.00
ARTEC EMA Mail 6.92 - CSRF
ARTEC EMA Mail 6.92 allows CSRF.
CWE-352 May 12, 2025
CVE-2025-4375 EPSS 0.00
Sparx Systems Pro Cloud Server <6.0.165 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165.
CWE-352 May 09, 2025
CVE-2025-20195 4.3 MEDIUM EPSS 0.00
Cisco IOS XE - CSRF
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an already authenticated user to follow a crafted link. A successful exploit could allow the attacker to clear the syslog, parser, and licensing logs on the affected device if the targeted user has privileges to clear those logs.
CWE-352 May 07, 2025
CVE-2025-47685 7.1 HIGH EPSS 0.00
Moloni Contribuinte Checkout <2.0.02 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout allows Stored XSS. This issue affects Contribuinte Checkout: from n/a through 2.0.02.
CWE-352 May 07, 2025
CVE-2025-47684 5.4 MEDIUM EPSS 0.00
Smaily for WP <3.1.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP allows Cross Site Request Forgery. This issue affects Smaily for WP: from n/a through 3.1.6.
CWE-352 May 07, 2025
CVE-2025-47681 4.3 MEDIUM EPSS 0.00
Ability, Inc Web Accessibility <2.0.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access allows Cross Site Request Forgery. This issue affects Web Accessibility with Max Access: from n/a through 2.0.9.
CWE-352 May 07, 2025
CVE-2025-47674 4.3 MEDIUM EPSS 0.00
Credova Financial <2.5.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Credova Financial Credova_Financial allows Cross Site Request Forgery. This issue affects Credova_Financial: from n/a through 2.5.0.
CWE-352 May 07, 2025
CVE-2025-47667 5.4 MEDIUM EPSS 0.00
qusupport LiveAgent <4.4.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7.
CWE-352 May 07, 2025
CVE-2025-47661 5.4 MEDIUM EPSS 0.00
codemstory WordPress SimplePay <5.2.11 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.
CWE-352 May 07, 2025
CVE-2025-47655 7.1 HIGH EPSS 0.00
theMarketer <1.4.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer allows Stored XSS. This issue affects theMarketer: from n/a through 1.4.7.
CWE-352 May 07, 2025
CVE-2025-47648 7.1 HIGH EPSS 0.00
axima Pays - WooCommerce Payment Gateway <2.6 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway allows Stored XSS. This issue affects Pays – WooCommerce Payment Gateway: from n/a through 2.6.
CWE-352 May 07, 2025