CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
216 results Clear all
CVE-2026-28722 7.3 HIGH EPSS 0.00
Acronis Cyber Protect 17 - Privilege Escalation
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
CWE-610 Mar 06, 2026
CVE-2026-28721 7.3 HIGH EPSS 0.00
Acronis Cyber Protect 17 - Privilege Escalation
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
CWE-610 Mar 06, 2026
CVE-2025-48654 7.8 HIGH EPSS 0.00
CompanionDeviceManagerService - Privilege Escalation
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-610 Mar 02, 2026
CVE-2026-3404 5.0 MEDIUM EPSS 0.00
thinkgem JeeSite <=5.15.1 - XXE
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-611 Mar 02, 2026
CVE-2026-2536 6.3 MEDIUM EPSS 0.00
opencc JFlow <20260129 - XXE
A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. This manipulation of the argument File causes xml external entity reference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CWE-611 Feb 16, 2026
CVE-2026-2074 6.3 MEDIUM EPSS 0.00
O2OA <9.0.0 - SSRF
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-610 Feb 07, 2026
CVE-2026-1218 6.3 MEDIUM EPSS 0.00
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClientService.class of the component com.artery.richclient.RichClientService. Performing a manipulation results in xml external entity reference. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-611 Jan 20, 2026
CVE-2025-15251 5.6 MEDIUM 2 PoCs EPSS 0.00
beecue FastBee <2.1 - XML External Entity Reference
A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The project owner replied to the issue report: "Okay, we'll handle it as soon as possible."
CWE-611 Dec 30, 2025
CVE-2025-68478 7.1 HIGH EPSS 0.00
Langflow <1.7.0 - Path Traversal
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at that path. There is no path restriction, normalization, or allowed directory enforcement, so absolute paths (e.g., /etc/poc.txt) are interpreted as is. Version 1.7.0 fixes the issue.
CWE-610 Dec 19, 2025
CVE-2025-48598 6.6 MEDIUM EPSS 0.00
Face Unlock Settings - Privilege Escalation
In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-441 Dec 08, 2025
CVE-2025-13209 6.3 MEDIUM 1 Writeup EPSS 0.00
bestfeng oa_git_free <9.5 - XML External Entity Reference
A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CWE-611 Nov 15, 2025
CVE-2025-11341 7.3 HIGH EPSS 0.00
Jinher OA <2.0 - SSRF
A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
CWE-611 Oct 06, 2025
CVE-2025-11140 7.3 HIGH 1 Writeup EPSS 0.00
Bjskzy Zhiyou ERP <11.0 - SSRF
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-611 Sep 29, 2025
CVE-2025-11035 6.3 MEDIUM EPSS 0.00
Jinher OA 2.0 - SSRF
A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CWE-611 Sep 26, 2025
CVE-2025-10816 7.3 HIGH EPSS 0.00
Jinher OA - XXE
A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
CWE-611 Sep 22, 2025
CVE-2025-8057 6.5 MEDIUM EPSS 0.00
Patika Global Technologies HumanSuite <53.21.0 - Auth Bypass
Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerability in Patika Global Technologies HumanSuite allows Exploiting Trust in Client.This issue affects HumanSuite: before 53.21.0.
CWE-639 Sep 16, 2025
CVE-2025-9065 8.8 HIGH EPSS 0.00
Rockwell Automation ThinManager - SSRF
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.
CWE-610 Sep 09, 2025
CVE-2025-10092 7.3 HIGH EPSS 0.00
Jinher OA < 1.2 - XXE
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.
CWE-611 Sep 08, 2025
CVE-2025-10091 7.3 HIGH EPSS 0.00
Jinher OA < 1.2 - XXE
A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CWE-611 Sep 08, 2025
CVE-2024-49728 5.5 MEDIUM EPSS 0.00
Java - Info Disclosure
In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-610 Sep 02, 2025