CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2025-47514 7.1 HIGH EPSS 0.00
Eli ELI's Related Posts Footer Links and Widget <1.2.04.20 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget allows Stored XSS. This issue affects ELI's Related Posts Footer Links and Widget: from n/a through 1.2.04.20.
CWE-352 May 07, 2025
CVE-2025-47491 7.4 HIGH EPSS 0.00
A WP Life Contact Form Widget <1.4.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery. This issue affects Contact Form Widget: from n/a through 1.4.6.
CWE-352 May 07, 2025
CVE-2025-47473 5.4 MEDIUM EPSS 0.00
pimwick PW WooCommerce Bulk Edit - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.
CWE-352 May 07, 2025
CVE-2025-47470 4.3 MEDIUM EPSS 0.00
senols GPT3 AI Content Writer <1.9.14 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in senols GPT3 AI Content Writer allows Cross Site Request Forgery. This issue affects GPT3 AI Content Writer: from n/a through 1.9.14.
CWE-352 May 07, 2025
CVE-2025-47468 4.3 MEDIUM EPSS 0.00
Hash Form <1.2.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form allows Cross Site Request Forgery. This issue affects Hash Form: from n/a through 1.2.8.
CWE-352 May 07, 2025
CVE-2025-47466 5.4 MEDIUM EPSS 0.00
Rustaurius Ultimate WP Mail <1.3.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
CWE-352 May 07, 2025
CVE-2025-47462 8.8 HIGH EPSS 0.00
Ohidul Islam Challan <3.7.58 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ohidul Islam Challan allows Privilege Escalation. This issue affects Challan: from n/a through 3.7.58.
CWE-352 May 07, 2025
CVE-2025-47459 4.3 MEDIUM EPSS 0.00
XpeedStudio WP Fundraising Donation & Crowdfunding - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in XpeedStudio WP Fundraising Donation and Crowdfunding Platform allows Cross Site Request Forgery. This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.7.3.
CWE-352 May 07, 2025
CVE-2025-47451 4.3 MEDIUM EPSS 0.00
silverplugins217 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce allows Cross Site Request Forgery. This issue affects Product Quantity Dropdown For Woocommerce: from n/a through 1.2.
CWE-352 May 07, 2025
CVE-2025-47448 4.3 MEDIUM EPSS 0.00
ThimPress WP Hotel Booking <2.1.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
CWE-352 May 07, 2025
CVE-2025-47447 4.3 MEDIUM EPSS 0.00
Hossni Mubarak Cool Author Box <3.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0.
CWE-352 May 07, 2025
CVE-2025-47446 4.3 MEDIUM EPSS 0.00
Listamester <2.3.6 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in listamester Listamester allows Cross Site Request Forgery. This issue affects Listamester: from n/a through 2.3.6.
CWE-352 May 07, 2025
CVE-2025-0669 8.8 HIGH EPSS 0.00
BOINC Server <1.4.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.
CWE-352 May 07, 2025
CVE-2025-4327 4.3 MEDIUM EPSS 0.00
Mrcms - Missing Authorization
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
CWE-862 May 06, 2025
CVE-2025-4337 4.3 MEDIUM EPSS 0.00
AHAthat Plugin <1.6 - CSRF
The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the aha_plugin_page() function. This makes it possible for unauthenticated attackers to delete AHA pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 06, 2025
CVE-2025-4282 4.3 MEDIUM 1 Writeup EPSS 0.00
SourceCodester/oretnom23 Stock Management System 1.0 - CSRF
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-862 May 05, 2025
CVE-2025-28062 8.1 HIGH 2 PoCs Analysis EPSS 0.00
Frappe Erpnext - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
CWE-352 May 05, 2025
CVE-2025-4199 6.1 MEDIUM EPSS 0.00
Abundatrade Plugin <1.8.02 - CSRF
The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to missing or incorrect nonce validation on the 'abundatrade' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 03, 2025
CVE-2025-4198 6.1 MEDIUM EPSS 0.00
Alink Tap <1.3.1 - CSRF
The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the 'alink-tap' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 03, 2025
CVE-2025-4188 6.1 MEDIUM EPSS 0.00
WordPress Advanced Reorder Image Text Slider <1.0 - CSRF
The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'reorder-simple-image-text-slider-setting' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 May 03, 2025