Critical Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,101 results
Clear all
CVE-2025-39596
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Quentn WP <1.2.8 - Privilege Escalation
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.
CWE-1390
Apr 17, 2025
CVE-2025-39436
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.00
aidraw I Draw <1.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.
CWE-434
Apr 17, 2025
CVE-2025-32682
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.00
RomanCode MapSVG Lite <8.5.34 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.
CWE-434
Apr 17, 2025
CVE-2025-32583
9.9
CRITICAL
3 PoCs
Analysis
EPSS 0.00
termel PDF 2 Post <2.4.0 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.
CWE-94
Apr 17, 2025
CVE-2025-39601
9.6
CRITICAL
2 PoCs
Analysis
EPSS 0.00
WPFactory Custom CSS, JS & PHP <2.4.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1.
CWE-352
Apr 16, 2025
CVE-2025-32579
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.00
SoftClever Limited Sync Posts <1.0 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.
CWE-434
Apr 11, 2025
CVE-2025-32206
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.00
LABCAT Processing Projects <1.0.2 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2.
CWE-434
Apr 10, 2025
CVE-2025-32140
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
CWE-434
Apr 10, 2025
CVE-2025-32641
9.6
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Anant Addons for Elementor <1.1.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.
CWE-352
Apr 09, 2025
CVE-2025-31033
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Buddypress Humanity <1.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.
CWE-352
Apr 09, 2025
CVE-2025-32118
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.00
NiteoThemes CMP - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
CWE-434
Apr 04, 2025
CVE-2025-30911
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.
CWE-94
Apr 01, 2025
CVE-2025-28915
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.25
ThemeEgg ToolKit <1.2.9 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.
CWE-434
Mar 11, 2025
CVE-2025-1307
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.28
Spicethemes Newscrunch < 1.8.4.1 - Missing Authorization
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-862
Mar 04, 2025
CVE-2025-25101
9.6
CRITICAL
2 PoCs
Analysis
EPSS 0.01
MetricThemes Munk Sites <1.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.
CWE-352
Feb 07, 2025
CVE-2025-23942
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.45
NgocCode WP Load Gallery <2.1.6 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Upload a Web Shell to a Web Server.This issue affects WP Load Gallery: from n/a through <= 2.1.6.
CWE-434
Jan 22, 2025
CVE-2025-23922
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.03
Harsh iSpring Embedder - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a Web Server.This issue affects iSpring Embedder: from n/a through <= 1.0.
CWE-352
Jan 16, 2025
CVE-2025-67494
9.3
CRITICAL
1 PoC
Analysis
EPSS 0.00
Zitadel < 4.7.1 - SSRF
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
CWE-918
Dec 09, 2025
CVE-2025-60854
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
D-Link R15 (AX1500) <1.20.01 - Command Injection
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
CWE-77
Dec 02, 2025
CVE-2025-50165
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Microsoft Graphics Component - RCE
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CWE-822
Aug 12, 2025