CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
256 results Clear all
CVE-2025-55155 5.4 MEDIUM 1 Writeup EPSS 0.00
MantisBT <2.27.1 - Info Disclosure
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail address, the system saves it without validating that it actually belongs to the user. This could result in storing an invalid email address, preventing the user from receiving system notifications. Notifications sent to another person's email address could lead to information disclosure. This issue is fixed in version 2.27.2.
CWE-201 Nov 04, 2025
CVE-2025-64351 4.3 MEDIUM EPSS 0.00
Rank Math SEO <1.0.252.1 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
CWE-201 Oct 31, 2025
CVE-2025-62979 5.3 MEDIUM EPSS 0.00
airesvsg ACF to REST API <3.3.4 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retrieve Embedded Sensitive Data.This issue affects ACF to REST API: from n/a through <= 3.3.4.
CWE-201 Oct 27, 2025
CVE-2025-62947 7.5 HIGH EPSS 0.00
Publitio <2.2.3 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in publitio Publitio publitio allows Retrieve Embedded Sensitive Data.This issue affects Publitio: from n/a through <= 2.2.3.
CWE-201 Oct 27, 2025
CVE-2025-62895 7.5 HIGH EPSS 0.00
Atarim Visual Collaboration <4.2 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.
CWE-201 Oct 27, 2025
CVE-2025-62062 5.3 MEDIUM EPSS 0.00
ThemeRuby Easy Post Submission <=1.7.0 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Retrieve Embedded Sensitive Data.This issue affects Easy Post Submission: from n/a through <= 1.7.0.
CWE-201 Oct 22, 2025
CVE-2025-62026 4.3 MEDIUM EPSS 0.00
Blockspare - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Blockspare Blockspare blockspare allows Retrieve Embedded Sensitive Data.This issue affects Blockspare: from n/a through <= 3.2.13.2.
CWE-201 Oct 22, 2025
CVE-2025-59579 7.5 HIGH EPSS 0.00
Simple Job Board <2.13.7 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7.
CWE-201 Oct 22, 2025
CVE-2025-59578 5.8 MEDIUM EPSS 0.00
ShopMagic <4.5.6 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects ShopMagic: from n/a through <= 4.5.6.
CWE-201 Oct 22, 2025
CVE-2025-53232 5.8 MEDIUM EPSS 0.00
inkthemes WP Gmail SMTP <1.0.7 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Retrieve Embedded Sensitive Data.This issue affects WP Gmail SMTP: from n/a through <= 1.0.7.
CWE-201 Oct 22, 2025
CVE-2025-53218 5.8 MEDIUM EPSS 0.00
Saad Iqbal AppExperts <1.4.5 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal AppExperts appexperts allows Retrieve Embedded Sensitive Data.This issue affects AppExperts: from n/a through <= 1.4.5.
CWE-201 Oct 22, 2025
CVE-2025-59268 5.3 MEDIUM EPSS 0.00
BIG-IP - Info Disclosure
On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE-201 Oct 15, 2025
CVE-2024-47569 4.3 MEDIUM EPSS 0.00
Fortinet FortiMail <7.4.3 - Info Disclosure
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiNDR 1.5 all versions, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.4, FortiProxy 7.2.0 through 7.2.10, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiTester 7.4.0 through 7.4.2, FortiTester 7.3 all versions, FortiTester 7.2 all versions, FortiTester 7.1 all versions, FortiTester 7.0 all versions, FortiTester 4.2 all versions, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0.7 through 6.0.12, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions, FortiWeb 6.4 all versions allows attacker to disclose sensitive information via specially crafted packets.
CWE-201 Oct 14, 2025
CVE-2025-43825 6.5 MEDIUM EPSS 0.00
Liferay Portal <7.4.3.132 & DXP - Info Disclosure
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.
CWE-201 Oct 03, 2025
CVE-2025-11025 5.3 MEDIUM EPSS 0.00
Vimesoft Corporate Messaging Platform <2.0.0 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.
CWE-201 Sep 26, 2025
CVE-2025-9958 7.7 HIGH EPSS 0.00
GitLab CE/EE <18.2.7-18.4.1 - Info Disclosure
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
CWE-201 Sep 26, 2025
CVE-2025-60140 5.3 MEDIUM EPSS 0.00
The Tribal <1.3.3 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal allows Retrieve Embedded Sensitive Data. This issue affects The Tribal: from n/a through 1.3.3.
CWE-201 Sep 26, 2025
CVE-2025-60125 5.3 MEDIUM EPSS 0.00
FoodBook <4.7.1 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook allows Retrieve Embedded Sensitive Data. This issue affects FoodBook: from n/a through 4.7.1.
CWE-201 Sep 26, 2025
CVE-2025-60095 4.3 MEDIUM EPSS 0.00
Benjamin Intal Stackable <3.18.1 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable allows Retrieve Embedded Sensitive Data. This issue affects Stackable: from n/a through 3.18.1.
CWE-201 Sep 26, 2025
CVE-2025-59010 7.5 HIGH EPSS 0.00
Permalink Manager Lite <2.5.1.3 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite allows Retrieve Embedded Sensitive Data. This issue affects Permalink Manager Lite: from n/a through 2.5.1.3.
CWE-201 Sep 26, 2025