Critical Vulnerabilities with Public Exploits

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
4,101 results Clear all
CVE-2025-66802 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Sourcecodester Covid-19 Contact Tracing System 1.0 - RCE
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
CWE-434 Jan 12, 2026
CVE-2025-67325 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Webkul Qloapps < 1.7.0 - Unrestricted File Upload
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
CWE-434 Jan 08, 2026
CVE-2025-68705 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
RustFS <1.0.0-alpha.79 - Path Traversal
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79.
CWE-22 Jan 07, 2026
CVE-2025-49071 10.0 CRITICAL 1 PoC Analysis EPSS 0.01
NasaTheme Flozen - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell to a Web Server.This issue affects Flozen: from n/a through < 1.5.1.
CWE-434 Jun 17, 2025
CVE-2025-65354 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Puneethreddyhc Event Management - SQL Injection
Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.
CWE-89 Dec 23, 2025
CVE-2025-61246 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
indieka900 online-shopping-system-php 1.0 - SQL Injection
indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.
CWE-89 Jan 08, 2026
CVE-2025-11833 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.16
Post SMTP <3.6.0 - Info Disclosure
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to read arbitrary logged emails sent through the Post SMTP plugin, including password reset emails containing password reset links, which can lead to account takeover.
CWE-862 Nov 01, 2025
CVE-2025-1023 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.03
ChurchCRM <5.13.0 - SQL Injection
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.
CWE-89 Feb 18, 2025
CVE-2025-12674 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
KiotViet Sync <1.8.5 - RCE
The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434 Nov 05, 2025
CVE-2025-13390 10.0 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.37
Wpdirectorykit WP Directory Kit < 1.4.4 - Authentication Bypass
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
CWE-303 Dec 03, 2025
CVE-2025-14998 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.00
Branda WordPress <3.4.24 - Privilege Escalation
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
CWE-639 Jan 02, 2026
CVE-2025-64095 10.0 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.13
Dnnsoftware Dotnetnuke < 10.1.1 - Unrestricted File Upload
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.
CWE-434 Oct 28, 2025
CVE-2025-27515 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Laravel - Info Disclosure
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
CWE-155 Mar 05, 2025
CVE-2025-65741 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Sublime Text 3 <3208 - Code Injection
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application.
CWE-427 Dec 09, 2025
CVE-2025-61922 9.1 CRITICAL 2 PoCs Analysis EPSS 0.00
Prestashop Checkout < 7.4.4.1 - Authentication Bypass
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
CWE-287 Oct 16, 2025
CVE-2025-54322 10.0 CRITICAL 2 PoCs Analysis EPSS 0.00
Xspeeder Sxzos < 2025-12-26 - Code Injection
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
CWE-95 Dec 27, 2025
CVE-2025-46295 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Apache Commons Text <1.10.0 - RCE
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
CWE-94 Dec 16, 2025
CVE-2025-22777 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
Givewp < 3.19.4 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
CWE-502 Jan 13, 2025
CVE-2025-57105 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Dlink Di-7400g+ Firmware - Command Injection
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.
CWE-77 Aug 22, 2025
CVE-2025-68615 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
net-snmp <5.9.5-5.10.pre2 - Buffer Overflow
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
CWE-119 Dec 23, 2025