CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
8,801 results Clear all
CVE-2026-24596 4.7 MEDIUM EPSS 0.00
Related Posts Thumbnails Plugin <4.3.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through <= 4.3.1.
CWE-352 Jan 23, 2026
CVE-2026-24549 4.3 MEDIUM EPSS 0.00
GeoDirectory <2.8.150 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory allows Cross Site Request Forgery.This issue affects GeoDirectory: from n/a before 2.8.150.
CWE-352 Jan 23, 2026
CVE-2026-24542 4.3 MEDIUM EPSS 0.00
John James Jacoby WP Term Order <= 2.1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Term Order wp-term-order allows Cross Site Request Forgery.This issue affects WP Term Order: from n/a through <= 2.1.0.
CWE-352 Jan 23, 2026
CVE-2026-24521 4.3 MEDIUM EPSS 0.00
Kama Thumbnail <= 3.5.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request Forgery.This issue affects Kama Thumbnail: from n/a through <= 3.5.1.
CWE-352 Jan 23, 2026
CVE-2026-24384 5.4 MEDIUM EPSS 0.00
Merge + Minify + Refresh <2.15 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14.
CWE-352 Jan 22, 2026
CVE-2026-24374 5.4 MEDIUM EPSS 0.00
Metagauss RegistrationMagic <= 6.0.6.9 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9.
CWE-352 Jan 22, 2026
CVE-2026-24365 5.4 MEDIUM EPSS 0.00
WooCommerce Stock Manager <3.6.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through < 3.6.0.
CWE-352 Jan 22, 2026
CVE-2026-22483 5.4 MEDIUM EPSS 0.00
winkm89 teachPress <9.0.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in winkm89 teachPress teachpress allows Cross Site Request Forgery.This issue affects teachPress: from n/a through <= 9.0.12.
CWE-352 Jan 22, 2026
CVE-2026-22462 4.3 MEDIUM EPSS 0.00
richardevcom <1.4.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in richardevcom Add Polylang support for Customizer add-polylang-support-for-customizer allows Cross Site Request Forgery.This issue affects Add Polylang support for Customizer: from n/a through <= 1.4.5.
CWE-352 Jan 22, 2026
CVE-2026-22382 5.4 MEDIUM EPSS 0.00
Mikado-Themes PawFriends <1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
CWE-352 Jan 22, 2026
CVE-2026-22360 4.3 MEDIUM EPSS 0.00
SearchAzon <1.4 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This issue affects SearchAzon: from n/a through <= 1.4.
CWE-352 Jan 22, 2026
CVE-2026-22359 4.3 MEDIUM EPSS 0.00
AA-Team Wordpress Movies Bulk Importer - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross Site Request Forgery.This issue affects Wordpress Movies Bulk Importer: from n/a through <= 1.0.
CWE-352 Jan 22, 2026
CVE-2026-22355 7.1 HIGH EPSS 0.00
gregmolnar Simple XML Sitemap <=1.3 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.This issue affects Simple XML Sitemap: from n/a through <= 1.3.
CWE-352 Jan 22, 2026
CVE-2025-70899 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Phpgurukul Online Course Registration - CSRF
PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.
CWE-352 Jan 22, 2026
CVE-2025-67626 4.3 MEDIUM EPSS 0.00
Angel Costa WP SEO Search <2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Angel Costa WP SEO Search wp-seo-search allows Cross Site Request Forgery.This issue affects WP SEO Search: from n/a through <= 1.1.
CWE-352 Jan 22, 2026
CVE-2025-31413 8.8 HIGH EPSS 0.00
bdthemes Element Pack <8.3.13 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Cross Site Request Forgery.This issue affects Element Pack Elementor Addons: from n/a through <= 8.3.13.
CWE-352 Jan 22, 2026
CVE-2021-47860 5.3 MEDIUM 2 PoCs Analysis EPSS 0.00
GetSimple CMS Custom JS 0.1 - CSRF
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code on the hosting server when an authenticated administrator visits the page.
CWE-352 Jan 21, 2026
CVE-2021-47830 6.5 MEDIUM 2 PoCs Analysis EPSS 0.00
GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF
GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.
CWE-352 Jan 21, 2026
CVE-2025-36411 3.5 LOW EPSS 0.00
IBM Applinx - CSRF
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CWE-352 Jan 20, 2026
CVE-2026-1051 4.3 MEDIUM EPSS 0.00
Newsletter - WordPress <9.1.0 - CSRF
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.
CWE-352 Jan 20, 2026