CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
2,435 results Clear all
CVE-2025-52724 9.8 CRITICAL EPSS 0.00
BoldThemes Amwerk <1.2.0 - Object Injection
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk allows Object Injection. This issue affects Amwerk: from n/a through 1.2.0.
CWE-502 Jun 27, 2025
CVE-2025-28970 9.8 CRITICAL EPSS 0.00
WP Optimize By xTraffic <5.1.6 - Object Injection
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic allows Object Injection. This issue affects WP Optimize By xTraffic: from n/a through 5.1.6.
CWE-502 Jun 27, 2025
CVE-2025-53002 8.3 HIGH 1 Writeup EPSS 0.02
Hiyouga Llama-factory < 0.9.4 - Insecure Deserialization
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious attackers to execute arbitrary malicious code on the host system simply by passing a malicious `Checkpoint path` parameter through the `WebUI` interface. The attack is stealthy, as the victim remains unaware of the exploitation. The root cause is that the `vhead_file` argument is loaded without the secure parameter `weights_only=True`. Version 0.9.4 contains a fix for the issue.
CWE-502 Jun 26, 2025
CVE-2025-36038 9.0 CRITICAL EPSS 0.00
IBM Websphere Application Server < 8.5.5.28 - Insecure Deserialization
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
CWE-502 Jun 25, 2025
CVE-2025-2566 EPSS 0.01
Kaleris NAVIS N4 ULC - Code Injection
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.
CWE-502 Jun 24, 2025
CVE-2025-25034 EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.74
SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before passing it to the unserialize() function. This allows an unauthenticated attacker to submit crafted serialized data containing malicious object declarations, resulting in arbitrary code execution within the application context. Although SugarCRM released a prior fix in advisory sugarcrm-sa-2016-001, the patch was incomplete and failed to address some vectors. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-13 UTC.
CWE-502 Jun 20, 2025
CVE-2025-47771 1 Writeup EPSS 0.00
Com.powsybl Powsybl-math < 6.7.2 - Insecure Deserialization
PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in the read method of the SparseMatrix class that can lead to a wide range of privilege escalations depending on the circumstances. This method takes in an InputStream and returns a SparseMatrix object. This issue has been patched in com.powsybl:powsybl-math: 6.7.2. A workaround for this issue involves not using SparseMatrix deserialization (SparseMatrix.read(...) methods).
CWE-502 Jun 20, 2025
CVE-2025-6279 5.5 MEDIUM EPSS 0.00
Upsonic <0.55.6 - Deserialization
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used.
CWE-502 Jun 19, 2025
CVE-2025-49217 9.8 CRITICAL EPSS 0.02
Trendmicro Trend Micro Endpoint Encryption - Insecure Deserialization
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
CWE-502 Jun 17, 2025
CVE-2025-49214 8.8 HIGH EPSS 0.03
Trendmicro Trend Micro Endpoint Encryption - Insecure Deserialization
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
CWE-502 Jun 17, 2025
CVE-2025-49213 9.8 CRITICAL EPSS 0.04
Trendmicro Trend Micro Endpoint Encryption - Insecure Deserialization
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.
CWE-502 Jun 17, 2025
CVE-2025-49212 9.8 CRITICAL EPSS 0.04
Trendmicro Trend Micro Endpoint Encryption - Insecure Deserialization
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
CWE-502 Jun 17, 2025
CVE-2025-49220 9.8 CRITICAL EPSS 0.07
Trendmicro Apex Central - Insecure Deserialization
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.
CWE-502 Jun 17, 2025
CVE-2025-49219 9.8 CRITICAL EPSS 0.06
Trendmicro Apex Central - Insecure Deserialization
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.
CWE-502 Jun 17, 2025
CVE-2025-49331 7.2 HIGH EPSS 0.00
impleCode eCommerce Product Catalog <3.4.3 - Object Injection
Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog allows Object Injection. This issue affects eCommerce Product Catalog: from n/a through 3.4.3.
CWE-502 Jun 17, 2025
CVE-2025-49330 9.8 CRITICAL EPSS 0.00
CRM Perks Integration - Code Injection
Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin allows Object Injection. This issue affects Integration for Contact Form 7 and Zoho CRM, Bigin: from n/a through 1.3.0.
CWE-502 Jun 17, 2025
CVE-2025-31919 9.8 CRITICAL EPSS 0.00
themeton Spare <1.7 - Object Injection
Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7.
CWE-502 Jun 17, 2025
CVE-2025-30618 9.8 CRITICAL EPSS 0.00
yuliaz Rapyd Payment Extension <1.2.0 - Object Injection
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce allows Object Injection. This issue affects Rapyd Payment Extension for WooCommerce: from n/a through 1.2.0.
CWE-502 Jun 17, 2025
CVE-2025-24919 8.1 HIGH EPSS 0.00
Dell ControlVault3 <5.15.10.14-6.2.26.36 - Code Injection
A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.
CWE-502 Jun 13, 2025
CVE-2025-47166 8.8 HIGH 1 PoC Analysis EPSS 0.09
Microsoft Sharepoint Enterprise Server - Insecure Deserialization
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CWE-502 Jun 10, 2025