Vulnerabilities Exploited in the Wild with Public PoC

Updated 33m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
2,390 results Clear all
CVE-2025-2748 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.00
Kentico Xperience CMS - Unauthenticated Stored XSS
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
CWE-434 Mar 24, 2025
CVE-2025-47916 10.0 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.91
Invisioncommunity < 5.0.7 - Remote Code Execution
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.
CWE-1336 May 16, 2025
CVE-2025-5419 8.8 HIGH KEV 7 PoCs Analysis EPSS 0.03
Google Chrome < 137.0.7151.68 - Out-of-Bounds Write
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE-125 Jun 03, 2025
CVE-2025-0288 7.8 HIGH EXPLOITED RANSOMWARE 2 PoCs Analysis EPSS 0.00
Paragon Software - Memory Corruption
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Mar 03, 2025
CVE-2025-3054 8.8 HIGH EXPLOITED 1 PoC Analysis EPSS 0.01
WP User Frontend Pro <4.1.3 - Code Injection
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this requires the 'Private Message' module to be enabled and the Business version of the PRO software to be in use.
CWE-434 Jun 05, 2025
CVE-2025-21479 8.6 HIGH KEV 2 PoCs Analysis EPSS 0.00
Qualcomm Aqt1000 Firmware - Incorrect Authorization
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CWE-863 Jun 03, 2025
CVE-2025-48828 9.0 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.74
vBulletin - RCE
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.
CWE-424 May 27, 2025
CVE-2025-48827 10.0 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.78
vBulletin <6.0.3 - RCE
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
CWE-424 May 27, 2025
CVE-2025-4632 9.8 CRITICAL KEV 1 PoC Analysis NUCLEI EPSS 0.49
Samsung MagicINFO <21.1052 - Path Traversal
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
CWE-22 May 13, 2025
CVE-2025-4322 9.8 CRITICAL EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.31
Motors WordPress <5.6.67 - Privilege Escalation
The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.
CWE-620 May 20, 2025
CVE-2025-4428 7.2 HIGH KEV 4 PoCs Analysis EPSS 0.20
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
CWE-94 May 13, 2025
CVE-2025-4427 5.3 MEDIUM KEV 4 PoCs Analysis NUCLEI EPSS 0.91
Ivanti Endpoint Manager Mobile < 11.12.0.5 - Authentication Bypass
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
CWE-288 May 13, 2025
CVE-2025-42999 9.1 CRITICAL KEV RANSOMWARE 1 PoC Analysis EPSS 0.50
SAP NetWeaver Visual Composer Metadata Uploader - Code Injection
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
CWE-502 May 13, 2025
CVE-2025-4664 4.3 MEDIUM EXPLOITED 5 PoCs Analysis EPSS 0.00
Google Chrome <136.0.7103.113 - Info Disclosure
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
May 14, 2025
CVE-2025-32756 9.8 CRITICAL KEV RANSOMWARE 7 PoCs Analysis EPSS 0.22
Fortinet Fortimail < 7.0.9 - Out-of-Bounds Write
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
CWE-121 May 13, 2025
CVE-2025-2777 9.3 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.23
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
CWE-611 May 07, 2025
CVE-2025-32709 7.8 HIGH KEV 1 PoC Analysis EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.21014 - Use After Free
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE-416 May 13, 2025
CVE-2025-30400 7.8 HIGH KEV 1 PoC Analysis EPSS 0.01
Windows DWM - Use After Free
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CWE-416 May 13, 2025
CVE-2025-30397 7.5 HIGH KEV 4 PoCs Analysis EPSS 0.21
Microsoft Scripting Engine - RCE
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CWE-843 May 13, 2025
CVE-2025-47445 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.09
Themewinter Eventin < 4.0.27 - Path Traversal
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
CWE-23 May 14, 2025