Latest Vulnerabilities with Public Exploits
Updated 9m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,701 results
Clear all
CVE-2025-29557
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
ExaGrid EX10 6.3-7.0.1.P08 - Info Disclosure
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
CWE-284
Jul 31, 2025
CVE-2025-40766
5.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
Siemens Sinec Traffic Analyzer < 3.0 - Denial of Service
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack.
CWE-400
Aug 12, 2025
CVE-2025-51385
3.5
LOW
SSVC PoC
1 PoC
Analysis
EPSS 0.00
D-LINK DI-8200 <16.07.26A1 - Buffer Overflow
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
CWE-121
Jul 31, 2025
CVE-2025-50867
6.5
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
CloudClassroom-PHP-Project 1.0 - SQL Injection
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
CWE-89
Jul 31, 2025
CVE-2025-50866
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
CloudClassroom-PHP-Project 1.0 - XSS
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking or phishing attacks.
CWE-79
Jul 31, 2025
CVE-2025-50481
4.8
MEDIUM
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
Mezzanine CMS 6.1.0 - XSS
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a blog post.
CWE-79
Jul 23, 2025
CVE-2025-7404
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.01
Gelbphoenix Autocaliweb - OS Command Injection
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
CWE-78
Jul 24, 2025
CVE-2025-6998
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Pypi Calibreweb - Denial of Service
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
CWE-1333
Jul 24, 2025
CVE-2025-54554
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
Tera Insights tiCrypt <2025-07-17 - Info Disclosure
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.
CWE-863
Aug 04, 2025
CVE-2025-53652
8.2
HIGH
1 PoC
Analysis
EPSS 0.00
Jenkins Git Parameter Plugin <439 - Command Injection
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
CWE-20
Jul 09, 2025
CVE-2025-5755
7.3
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Nikhil-bhalerao Open Source Clinic Management System - Injection
A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-74
Jun 06, 2025
CVE-2025-51411
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Institute-of-Current-Students v1.0 - XSS
A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email parameter in the /postquerypublic endpoint. The application fails to properly sanitize user input before reflecting it in the HTML response. This allows unauthenticated attackers to inject and execute arbitrary JavaScript code in the context of the victim's browser by tricking them into visiting a crafted URL or submitting a malicious form. Successful exploitation may lead to session hijacking, credential theft, or other client-side attacks.
CWE-79
Jul 25, 2025
CVE-2025-31486
5.3
MEDIUM
SSVC PoC
4 PoCs
Analysis
NUCLEI
EPSS 0.02
Vite server.fs.deny Bypass - Local File Inclusion
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than build.assetsInlineLimit (default: 4kB) and when using Vite 6.0+. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 4.5.12, 5.4.17, 6.0.14, 6.1.4, and 6.2.5.
CWE-200
Apr 03, 2025
CVE-2025-6558
8.8
HIGH
KEV
SSVC ACTIVE
2 PoCs
Analysis
EPSS 0.00
Google Chrome <138.0.7204.157 - RCE
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE-20
Jul 15, 2025
CVE-2025-50777
7.8
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera V1.00.02 - Incorrect Access Control
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems.
CWE-284
Jul 30, 2025
CVE-2025-8018
6.3
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Carmelo Food Ordering Review System - Injection
A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/reservation_page.php. The manipulation of the argument reg_Id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CWE-74
Jul 22, 2025
CVE-2025-7461
7.3
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Modern Bag 1.0 - SQL Injection
A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument proId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-74
Jul 12, 2025
CVE-2025-5025
4.8
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
libcurl - TLS Pinning
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.
CWE-295
May 28, 2025
CVE-2025-51403
6.5
MEDIUM
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
CWE-79
Jul 21, 2025
CVE-2025-51401
5.4
MEDIUM
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
CWE-79
Jul 21, 2025