CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
2,435 results Clear all
CVE-2025-48200 10.0 CRITICAL EPSS 0.01
Sjbr Sr-feuser-register < 12.5.0 - Insecure Deserialization
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.
CWE-502 May 21, 2025
CVE-2025-4803 7.2 HIGH 1 Writeup EPSS 0.01
Glossary by WPPedia - Code Injection
The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
CWE-502 May 21, 2025
CVE-2025-47277 9.8 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
Vllm < 0.8.5 - Insecure Deserialization
vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are affected. vLLM supports the use of the `PyNcclPipe` class to establish a peer-to-peer communication domain for data transmission between distributed nodes. The GPU-side KV-Cache transmission is implemented through the `PyNcclCommunicator` class, while CPU-side control message passing is handled via the `send_obj` and `recv_obj` methods on the CPU side.​ The intention was that this interface should only be exposed to a private network using the IP address specified by the `--kv-ip` CLI parameter. The vLLM documentation covers how this must be limited to a secured network. The default and intentional behavior from PyTorch is that the `TCPStore` interface listens on ALL interfaces, regardless of what IP address is provided. The IP address given was only used as a client-side address to use. vLLM was fixed to use a workaround to force the `TCPStore` instance to bind its socket to a specified private interface. As of version 0.8.5, vLLM limits the `TCPStore` socket to the private interface as configured.
CWE-502 May 20, 2025
CVE-2025-48018 7.5 HIGH EPSS 0.00
Unknown Product <Unknown Version - Privilege Escalation
An authenticated user can modify application state data.
CWE-502 May 20, 2025
CVE-2025-39356 9.8 CRITICAL EPSS 0.00
Chimpstudio Foodbakery Sticky Cart <3.2 - Object Injection
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through 3.2.
CWE-502 May 19, 2025
CVE-2025-39354 9.8 CRITICAL EPSS 0.00
Themegoods Grand Conference < 5.3 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference allows Object Injection.This issue affects Grand Conference: from n/a through 5.2.
CWE-502 May 19, 2025
CVE-2025-39349 9.8 CRITICAL EPSS 0.00
Potenzaglobalsolutions Ciyashop < 4.18.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.
CWE-502 May 19, 2025
CVE-2025-39348 9.8 CRITICAL EPSS 0.00
Themegoods Grand Restaurant < 7.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
CWE-502 May 19, 2025
CVE-2025-32928 9.8 CRITICAL EPSS 0.00
Themegoods Altair < 5.2.2 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.
CWE-502 May 19, 2025
CVE-2025-32927 9.8 CRITICAL EPSS 0.00
Chimpgroup Foodbakery < 3.3 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery allows Object Injection.This issue affects FoodBakery: from n/a through 3.3.
CWE-502 May 19, 2025
CVE-2025-47581 9.8 CRITICAL EPSS 0.00
Elbisnero WordPress Events Calendar Registration & Tickets <2.6.0 -...
Deserialization of Untrusted Data vulnerability in Elbisnero WordPress Events Calendar Registration & Tickets allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.
CWE-502 May 19, 2025
CVE-2025-39410 9.8 CRITICAL EPSS 0.00
themegusta Smart Sections Theme Builder - WPBakery Page Builder Add...
Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon.This issue affects Smart Sections Theme Builder - WPBakery Page Builder Addon: from n/a through 1.7.8.
CWE-502 May 19, 2025
CVE-2025-47582 9.8 CRITICAL EPSS 0.00
QuantumCloud WPBot Pro <12.7.0 - Code Injection
Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.
CWE-502 May 19, 2025
CVE-2025-4905 5.3 MEDIUM EPSS 0.00
Washington Basestation < 3.0.4 - Insecure Deserialization
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the file basestation3/QC.py. The manipulation of the argument qc_file leads to deserialization. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The code maintainer tagged the issue as closed. But there is no new commit nor release in the GitHub repository available so far.
CWE-502 May 19, 2025
CVE-2025-48134 7.2 HIGH EPSS 0.00
Shapedplugin WP Tabs < 2.2.11 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.
CWE-502 May 16, 2025
CVE-2025-4742 5.3 MEDIUM EPSS 0.00
XU-YIJIE grpo-flat <9024b43f091e2eb9bac65802b120c0b35f9ba856 - Dese...
A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9ba856. Affected is the function main of the file grpo_vanilla.py. The manipulation leads to deserialization. Local access is required to approach this attack. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-502 May 16, 2025
CVE-2025-4740 5.3 MEDIUM EPSS 0.00
BeamCtrl Airiana <11.0 - Deserialization
A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file coef. The manipulation leads to deserialization. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
CWE-502 May 16, 2025
CVE-2025-47784 9.8 CRITICAL 1 Writeup EPSS 0.01
Emlog < 2.5.14 - Insecure Deserialization
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return `false`. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.
CWE-502 May 15, 2025
CVE-2025-4701 5.3 MEDIUM EPSS 0.00
VITA-MLLM Freeze-Omni <20250421 - Deserialization
A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host.
CWE-502 May 15, 2025
CVE-2025-47292 1 Writeup EPSS 0.05
Cap Collectif <commit 812f2a7d271b76deab1175bdaf2be0b8102dd198 - RCE
Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user. Exploitation of this vulnerability can lead to Remote Code Execution. The vulnerability is fixed in commit 812f2a7d271b76deab1175bdaf2be0b8102dd198.
CWE-502 May 14, 2025