CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
8,801 results Clear all
CVE-2025-46513 4.3 MEDIUM EPSS 0.00
Codebangers All in One Time Clock Lite - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Codebangers All in One Time Clock Lite allows Cross Site Request Forgery. This issue affects All in One Time Clock Lite: from n/a through 1.3.324.
CWE-352 Apr 24, 2025
CVE-2025-46512 7.1 HIGH EPSS 0.00
Shamim Hasan Custom Functions Plugin - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shamim Hasan Custom Functions Plugin allows Stored XSS. This issue affects Custom Functions Plugin: from n/a through 1.1.
CWE-352 Apr 24, 2025
CVE-2025-46510 7.1 HIGH EPSS 0.00
Contact Form 7 Calendar <3.0.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in harrysudana Contact Form 7 Calendar allows Stored XSS. This issue affects Contact Form 7 Calendar: from n/a through 3.0.1.
CWE-352 Apr 24, 2025
CVE-2025-46508 7.1 HIGH EPSS 0.00
kasonzhao Advanced lazy load <1.6.0 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao Advanced lazy load allows Stored XSS. This issue affects Advanced lazy load: from n/a through 1.6.0.
CWE-352 Apr 24, 2025
CVE-2025-46507 7.1 HIGH EPSS 0.00
ldrumm Unsafe Mimetypes <0.1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes allows Stored XSS. This issue affects Unsafe Mimetypes: from n/a through 0.1.4.
CWE-352 Apr 24, 2025
CVE-2025-46506 7.1 HIGH EPSS 0.00
Lora77 WpZon - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Lora77 WpZon – Amazon Affiliate Plugin allows Reflected XSS. This issue affects WpZon – Amazon Affiliate Plugin: from n/a through 1.3.
CWE-352 Apr 24, 2025
CVE-2025-46504 7.1 HIGH EPSS 0.00
Vasaio QR Code <1.2.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Olar Marius Vasaio QR Code allows Stored XSS. This issue affects Vasaio QR Code: from n/a through 1.2.5.
CWE-352 Apr 24, 2025
CVE-2025-46498 5.4 MEDIUM EPSS 0.00
Zalo Official Live Chat <1.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat allows Cross Site Request Forgery. This issue affects Zalo Official Live Chat: from n/a through 1.0.0.
CWE-352 Apr 24, 2025
CVE-2025-46497 7.1 HIGH EPSS 0.00
Navegg Navegg Analytics <3.3.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Navegg Navegg Analytics allows Stored XSS. This issue affects Navegg Analytics: from n/a through 3.3.3.
CWE-352 Apr 24, 2025
CVE-2025-46495 6.5 MEDIUM EPSS 0.00
tomontoast Drop Caps <2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in tomontoast Drop Caps allows Stored XSS. This issue affects Drop Caps: from n/a through 2.1.
CWE-352 Apr 24, 2025
CVE-2025-46492 7.1 HIGH EPSS 0.00
Pham Thanh Call Now PHT Blog <2.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Pham Thanh Call Now PHT Blog allows Stored XSS. This issue affects Call Now PHT Blog: from n/a through 2.4.1.
CWE-352 Apr 24, 2025
CVE-2025-46466 7.1 HIGH EPSS 0.00
FelixTZ Modern Polls -<1.0.10 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls allows Stored XSS. This issue affects Modern Polls: from n/a through 1.0.10.
CWE-352 Apr 24, 2025
CVE-2025-46465 7.1 HIGH EPSS 0.00
Print Science Designer - Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer allows Stored XSS. This issue affects Print Science Designer: from n/a through 1.3.155.
CWE-352 Apr 24, 2025
CVE-2025-46462 4.3 MEDIUM EPSS 0.00
WPVN <=0.7.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Trân Minh-Quân WPVN allows Cross Site Request Forgery. This issue affects WPVN: from n/a through 0.7.8.
CWE-352 Apr 24, 2025
CVE-2025-46457 7.1 HIGH EPSS 0.00
Wp Custom CMS Block <2.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in digontoahsan Wp Custom CMS Block allows Stored XSS. This issue affects Wp Custom CMS Block: from n/a through 2.1.
CWE-352 Apr 24, 2025
CVE-2025-46452 7.1 HIGH EPSS 0.00
Olav Kolbu Google News <2.5.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Olav Kolbu Google News allows Stored XSS. This issue affects Google News: from n/a through 2.5.1.
CWE-352 Apr 24, 2025
CVE-2025-46450 7.1 HIGH EPSS 0.00
Occupancyplan <1.0.3.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan allows Stored XSS. This issue affects occupancyplan: from n/a through 1.0.3.0.
CWE-352 Apr 24, 2025
CVE-2025-46442 7.1 HIGH EPSS 0.00
Casey Johnson Loan Calculator <1.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator allows Stored XSS. This issue affects Loan Calculator: from n/a through 1.3.
CWE-352 Apr 24, 2025
CVE-2025-46439 7.4 HIGH EPSS 0.00
Vladimir Prelovac Plugin Central <2.5.1 - CSRF/Path Traversal
Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Plugin Central allows Path Traversal. This issue affects Plugin Central: from n/a through 2.5.1.
CWE-352 Apr 24, 2025
CVE-2025-46436 4.3 MEDIUM EPSS 0.00
SCSS-Library <0.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library allows Cross Site Request Forgery. This issue affects SCSS-Library: from n/a through 0.4.1.
CWE-352 Apr 24, 2025