CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
2,435 results Clear all
CVE-2025-32662 8.8 HIGH EPSS 0.00
Stylemix uListing <2.2.0 - Code Injection
Deserialization of Untrusted Data vulnerability in Stylemix uListing allows Object Injection. This issue affects uListing: from n/a through 2.2.0.
CWE-502 Apr 17, 2025
CVE-2025-32658 9.8 CRITICAL EPSS 0.00
wpWax HelpGent <2.2.4 - Code Injection
Deserialization of Untrusted Data vulnerability in wpWax HelpGent allows Object Injection. This issue affects HelpGent: from n/a through 2.2.4.
CWE-502 Apr 17, 2025
CVE-2025-32647 8.8 HIGH EPSS 0.00
PickPlugins Question Answer <1.2.70 - Object Injection
Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.
CWE-502 Apr 17, 2025
CVE-2025-32572 9.8 CRITICAL EPSS 0.00
Climax Themes Kata Plus <1.5.2 - Code Injection
Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus allows Object Injection. This issue affects Kata Plus: from n/a through 1.5.2.
CWE-502 Apr 17, 2025
CVE-2025-32571 8.8 HIGH EPSS 0.00
TuriTop Booking System <1.0.10 - Object Injection
Deserialization of Untrusted Data vulnerability in turitop TuriTop Booking System allows Object Injection. This issue affects TuriTop Booking System: from n/a through 1.0.10.
CWE-502 Apr 17, 2025
CVE-2025-27287 9.8 CRITICAL EPSS 0.00
SS Quiz <2.0.5 - Object Injection
Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz allows Object Injection. This issue affects SS Quiz: from n/a through 2.0.5.
CWE-502 Apr 17, 2025
CVE-2025-27286 9.8 CRITICAL EPSS 0.00
Saoshyant Slider <3.0 - Code Injection
Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider allows Object Injection. This issue affects Saoshyant Slider: from n/a through 3.0.
CWE-502 Apr 17, 2025
CVE-2025-39565 6.6 MEDIUM EPSS 0.00
Melapress Login Security < 2.1.1 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security allows Object Injection. This issue affects MelaPress Login Security: from n/a through 2.1.0.
CWE-502 Apr 16, 2025
CVE-2025-3677 5.3 MEDIUM EPSS 0.00
lm-sys fastchat <0.2.36 - Deserialization
A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low_cpu_mem of the file fastchat/model/apply_delta.py. The manipulation leads to deserialization. An attack has to be approached locally.
CWE-502 Apr 16, 2025
CVE-2025-30985 9.8 CRITICAL EPSS 0.00
GNUCommerce <1.5.4 - Code Injection
Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.
CWE-502 Apr 15, 2025
CVE-2025-3622 5.5 MEDIUM EPSS 0.00
Xorbits Inference <1.4.1 - Deserialization
A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.
CWE-502 Apr 15, 2025
CVE-2025-3590 6.3 MEDIUM EPSS 0.00
Adianti Framework <8.0 - Deserialization
A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.1 is able to address this issue. It is recommended to upgrade the affected component.
CWE-502 Apr 14, 2025
CVE-2025-31935 6.2 MEDIUM EPSS 0.00
Subnet Solutions PowerSYSTEM Center - DoS
Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition.
CWE-502 Apr 11, 2025
CVE-2025-3439 9.8 CRITICAL EPSS 0.04
Wpeverest Everest Forms < 3.1.2 - Insecure Deserialization
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
CWE-502 Apr 11, 2025
CVE-2025-31932 8.8 HIGH EPSS 0.00
BizRobo! - Code Injection
Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.
CWE-502 Apr 11, 2025
CVE-2025-32607 9.8 CRITICAL EPSS 0.00
WpBookingly <1.2.0 - Object Injection
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly allows Object Injection. This issue affects WpBookingly: from n/a through 1.2.0.
CWE-502 Apr 11, 2025
CVE-2025-32569 9.8 CRITICAL EPSS 0.00
TableOn - WordPress Posts Table Filterable <1.0.2 - Code Injection
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Object Injection. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.2.
CWE-502 Apr 11, 2025
CVE-2025-32568 9.8 CRITICAL EPSS 0.00
Empik Place for Woocommerce <1.4.2 - Object Injection
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2.
CWE-502 Apr 11, 2025
CVE-2025-32144 8.8 HIGH EPSS 0.00
PickPlugins Job Board Manager <2.1.60 - Object Injection
Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager allows Object Injection. This issue affects Job Board Manager: from n/a through 2.1.60.
CWE-502 Apr 11, 2025
CVE-2025-32143 8.8 HIGH EPSS 0.00
PickPlugins Accordion <2.3.10 - Code Injection
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion allows Object Injection. This issue affects Accordion: from n/a through 2.3.10.
CWE-502 Apr 11, 2025