Critical Vulnerabilities with Public Exploits

Updated 35m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,402 CVEs tracked 53,629 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,301 vendors 43,863 researchers
4,101 results Clear all
CVE-2025-4632 9.8 CRITICAL KEV 1 PoC Analysis NUCLEI EPSS 0.49
Samsung MagicINFO <21.1052 - Path Traversal
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
CWE-22 May 13, 2025
CVE-2025-49223 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Naver Billboard.js < 3.15.1 - Prototype Pollution
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CWE-1321 Jun 04, 2025
CVE-2025-44148 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.15
Mailenable < 10.00 - XSS
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CWE-79 Jun 03, 2025
CVE-2025-27590 9.0 CRITICAL 1 PoC Analysis EPSS 0.13
Oxidized Web < 0.15.0 - Path Traversal
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
CWE-22 Mar 03, 2025
CVE-2025-5329 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Martcode Software Inc. Delta Course Automation through 04022026 <4.02.2026 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection.This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-89 Feb 04, 2026
CVE-2025-5319 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
DIGITA Efficiency Management System <03022026 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection.This issue affects DIGITA Efficiency Management System: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-89 Feb 03, 2026
CVE-2025-4094 9.8 CRITICAL 3 PoCs Analysis EPSS 0.03
DIGITS: WordPress Mobile <8.4.6.1 - Info Disclosure
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
May 21, 2025
CVE-2025-4389 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Crawlomatic Multipage Scraper Post Generator <2.6.8.1 - File Upload
The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434 May 17, 2025
CVE-2025-2907 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.10
Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update
The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.
CWE-352 Apr 26, 2025
CVE-2025-25014 9.1 CRITICAL 1 PoC Analysis EPSS 0.03
Kibana - Code Injection
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
CWE-1321 May 06, 2025
CVE-2025-5058 9.8 CRITICAL 1 PoC Analysis EPSS 0.02
eMagicOne Store Manager <1.2.5 - RCE
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.
CWE-434 May 24, 2025
CVE-2025-66576 9.8 CRITICAL 1 PoC Analysis EPSS 0.01
Remote Keyboard Desktop 1.0.1 - Code Injection
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.
CWE-78 Dec 04, 2025
CVE-2025-4822 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
ScadaWatt Otopilot <27.05.2025 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.
CWE-89 Jul 24, 2025
CVE-2025-4784 9.8 CRITICAL 1 PoC EPSS 0.00
Moderec Tourtella < 26.05.2025 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue affects Tourtella: before 26.05.2025.
CWE-89 Jul 24, 2025
CVE-2025-4688 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
BGS Interactive SINAV.LINK <1.2 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects SINAV.LINK Exam Result Module: before 1.2.
CWE-89 Sep 16, 2025
CVE-2025-4603 9.1 CRITICAL 1 PoC Analysis EPSS 0.03
eMagicOne Store Manager - Path Traversal
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.
CWE-73 May 24, 2025
CVE-2025-2812 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Mydata Ticket Sales Automation < 2025-04-03 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).
CWE-89 May 02, 2025
CVE-2025-4403 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
WooCommerce 1.1.6 - RCE
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434 May 09, 2025
CVE-2025-46271 9.1 CRITICAL 1 PoC Analysis EPSS 0.06
UNI-NMS-Lite - Command Injection
UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.
CWE-78 Apr 24, 2025
CVE-2025-47549 9.1 CRITICAL 1 PoC Analysis EPSS 0.00
Themefic Ultimate Before After Image ... - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Server.This issue affects BEAF: from n/a through <= 4.6.10.
CWE-434 May 07, 2025