Critical Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,101 results Clear all
CVE-2025-39596 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Quentn WP <1.2.8 - Privilege Escalation
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.
CWE-1390 Apr 17, 2025
CVE-2025-39436 9.1 CRITICAL 2 PoCs Analysis EPSS 0.00
aidraw I Draw <1.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.
CWE-434 Apr 17, 2025
CVE-2025-32682 9.9 CRITICAL 2 PoCs Analysis EPSS 0.00
RomanCode MapSVG Lite <8.5.34 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.
CWE-434 Apr 17, 2025
CVE-2025-32583 9.9 CRITICAL 3 PoCs Analysis EPSS 0.00
termel PDF 2 Post <2.4.0 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.
CWE-94 Apr 17, 2025
CVE-2025-39601 9.6 CRITICAL 2 PoCs Analysis EPSS 0.00
WPFactory Custom CSS, JS & PHP <2.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1.
CWE-352 Apr 16, 2025
CVE-2025-32579 9.9 CRITICAL 2 PoCs Analysis EPSS 0.00
SoftClever Limited Sync Posts <1.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.
CWE-434 Apr 11, 2025
CVE-2025-32206 9.1 CRITICAL 2 PoCs Analysis EPSS 0.00
LABCAT Processing Projects <1.0.2 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2.
CWE-434 Apr 10, 2025
CVE-2025-32140 9.9 CRITICAL 2 PoCs Analysis EPSS 0.00
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
CWE-434 Apr 10, 2025
CVE-2025-32641 9.6 CRITICAL 2 PoCs Analysis EPSS 0.00
Anant Addons for Elementor <1.1.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.
CWE-352 Apr 09, 2025
CVE-2025-31033 9.8 CRITICAL 2 PoCs Analysis EPSS 0.00
Buddypress Humanity <1.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.
CWE-352 Apr 09, 2025
CVE-2025-32118 9.1 CRITICAL 2 PoCs Analysis EPSS 0.00
NiteoThemes CMP - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
CWE-434 Apr 04, 2025
CVE-2025-30911 9.9 CRITICAL 2 PoCs Analysis EPSS 0.02
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.
CWE-94 Apr 01, 2025
CVE-2025-28915 9.1 CRITICAL 3 PoCs Analysis EPSS 0.25
ThemeEgg ToolKit <1.2.9 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.
CWE-434 Mar 11, 2025
CVE-2025-1307 9.8 CRITICAL 2 PoCs Analysis EPSS 0.28
Spicethemes Newscrunch < 1.8.4.1 - Missing Authorization
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-862 Mar 04, 2025
CVE-2025-25101 9.6 CRITICAL 2 PoCs Analysis EPSS 0.01
MetricThemes Munk Sites <1.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.
CWE-352 Feb 07, 2025
CVE-2025-23942 9.1 CRITICAL 2 PoCs Analysis EPSS 0.45
NgocCode WP Load Gallery <2.1.6 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Upload a Web Shell to a Web Server.This issue affects WP Load Gallery: from n/a through <= 2.1.6.
CWE-434 Jan 22, 2025
CVE-2025-23922 10.0 CRITICAL 2 PoCs Analysis EPSS 0.03
Harsh iSpring Embedder - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a Web Server.This issue affects iSpring Embedder: from n/a through <= 1.0.
CWE-352 Jan 16, 2025
CVE-2025-67494 9.3 CRITICAL 1 PoC Analysis EPSS 0.00
Zitadel < 4.7.1 - SSRF
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
CWE-918 Dec 09, 2025
CVE-2025-60854 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
D-Link R15 (AX1500) <1.20.01 - Command Injection
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
CWE-77 Dec 02, 2025
CVE-2025-50165 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Microsoft Graphics Component - RCE
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CWE-822 Aug 12, 2025