CVE & Exploit Intelligence Database

Updated 50m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
2,435 results Clear all
CVE-2025-47660 8.8 HIGH EPSS 0.00
WC Affiliate <2.9.1 - Object Injection
Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate allows Object Injection. This issue affects WC Affiliate: from n/a through 2.9.1.
CWE-502 May 23, 2025
CVE-2025-47568 9.8 CRITICAL EPSS 0.00
Digitalzoomstudio Zoomsounds < 6.91 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds allows Object Injection. This issue affects ZoomSounds: from n/a through 6.91.
CWE-502 May 23, 2025
CVE-2025-47532 9.8 CRITICAL EPSS 0.00
CoinPayments <1.0.17 - Code Injection
Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce allows Object Injection. This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through 1.0.17.
CWE-502 May 23, 2025
CVE-2025-47530 9.8 CRITICAL EPSS 0.00
WPFunnels <3.5.18 - Code Injection
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.
CWE-502 May 23, 2025
CVE-2025-39503 9.8 CRITICAL EPSS 0.00
Goodlayers Hotel <3.1.4 - Object Injection
Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel allows Object Injection. This issue affects Goodlayers Hotel: from n/a through 3.1.4.
CWE-502 May 23, 2025
CVE-2025-39500 9.8 CRITICAL EPSS 0.00
Goodlayers Hostel <3.1.2 - Object Injection
Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel allows Object Injection. This issue affects Goodlayers Hostel: from n/a through 3.1.2.
CWE-502 May 23, 2025
CVE-2025-39499 9.8 CRITICAL EPSS 0.00
BoldThemes Medicare <2.1.0 - Code Injection
Deserialization of Untrusted Data vulnerability in BoldThemes Medicare allows Object Injection.This issue affects Medicare: from n/a through 2.1.0.
CWE-502 May 23, 2025
CVE-2025-39495 9.8 CRITICAL EPSS 0.00
BoldThemes Avantage -<2.4.6 - Code Injection
Deserialization of Untrusted Data vulnerability in BoldThemes Avantage allows Object Injection. This issue affects Avantage: from n/a through 2.4.6.
CWE-502 May 23, 2025
CVE-2025-39485 9.8 CRITICAL EPSS 0.00
Themegoods Grand Tour < 5.6 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.
CWE-502 May 23, 2025
CVE-2025-39480 9.8 CRITICAL EPSS 0.00
ThemeMakers Car Dealer <1.6.6 - Code Injection
Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer allows Object Injection. This issue affects Car Dealer: from n/a through 1.6.6.
CWE-502 May 23, 2025
CVE-2025-32293 8.8 HIGH EPSS 0.00
designthemes Finance Consultant <2.8 - Code Injection
Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant allows Object Injection. This issue affects Finance Consultant: from n/a through 2.8.
CWE-502 May 23, 2025
CVE-2025-32292 9.8 CRITICAL EPSS 0.00
AncoraThemes Jarvis - Night Club, Concert, Festival <1.8.11 - Deser...
Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress allows Object Injection. This issue affects Jarvis – Night Club, Concert, Festival WordPress: from n/a through 1.8.11.
CWE-502 May 23, 2025
CVE-2025-32284 8.8 HIGH EPSS 0.00
designthemes Pet World <2.8 - Code Injection
Deserialization of Untrusted Data vulnerability in designthemes Pet World allows Object Injection. This issue affects Pet World: from n/a through 2.8.
CWE-502 May 23, 2025
CVE-2025-31927 9.8 CRITICAL EPSS 0.00
Acerola <1.6.5 - Code Injection
Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5.
CWE-502 May 23, 2025
CVE-2025-31924 8.8 HIGH EPSS 0.00
designthemes Crafts & Arts <2.5 - Code Injection
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.
CWE-502 May 23, 2025
CVE-2025-31631 9.8 CRITICAL EPSS 0.00
AncoraThemes Fish House <1.2.7 - Code Injection
Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House allows Object Injection. This issue affects Fish House: from n/a through 1.2.7.
CWE-502 May 23, 2025
CVE-2025-31430 9.8 CRITICAL EPSS 0.00
The Business <1.6.1 - Code Injection
Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
CWE-502 May 23, 2025
CVE-2025-31423 9.8 CRITICAL EPSS 0.00
AncoraThemes Umberto -<1.2.8 - Object Injection
Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto allows Object Injection. This issue affects Umberto: from n/a through 1.2.8.
CWE-502 May 23, 2025
CVE-2025-31069 9.8 CRITICAL EPSS 0.00
HotStar - Multi-Purpose Business Theme <1.4 - Code Injection
Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.
CWE-502 May 23, 2025
CVE-2025-31049 9.8 CRITICAL EPSS 0.00
Meton Dash <1.3 - Code Injection
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.
CWE-502 May 23, 2025