Latest Vulnerabilities with Public Exploits

Updated 9m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,727 CVEs tracked 53,701 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,078 Nuclei templates 52,396 vendors 43,936 researchers
53,701 results Clear all
CVE-2025-51400 5.4 MEDIUM SSVC PoC 2 PoCs Analysis EPSS 0.00
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
CWE-79 Jul 21, 2025
CVE-2025-51398 5.4 MEDIUM SSVC PoC 2 PoCs Analysis EPSS 0.00
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
CWE-79 Jul 21, 2025
CVE-2025-51397 5.4 MEDIUM SSVC PoC 2 PoCs Analysis EPSS 0.01
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
CWE-779 Jul 21, 2025
CVE-2025-51396 5.4 MEDIUM SSVC PoC 2 PoCs Analysis EPSS 0.00
Live Helper Chat <4.60 - XSS
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
CWE-79 Jul 21, 2025
CVE-2025-7795 8.8 HIGH SSVC PoC 2 PoCs Analysis EPSS 0.12
Tenda FH451 1.0.0.9 - Buffer Overflow
A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-119 Jul 18, 2025
CVE-2025-7431 4.4 MEDIUM 1 PoC Analysis EPSS 0.00
WordPress Knowledge Base <2.3.1 - XSS
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CWE-79 Jul 18, 2025
CVE-2025-4380 8.1 HIGH 1 PoC Analysis NUCLEI EPSS 0.17
Scripteo Ads Pro < 4.89 - Remote File Inclusion
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site.
CWE-98 Jul 02, 2025
CVE-2025-7840 3.5 LOW SSVC PoC 1 PoC Analysis EPSS 0.00
Campcodes Online Movie Theater Seat Reservation System 1.0 - XSS
A vulnerability was found in Campcodes Online Movie Theater Seat Reservation System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=reserve of the component Reserve Your Seat Page. The manipulation of the argument Firstname/Lastname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-94 Jul 19, 2025
CVE-2025-51970 7.7 HIGH 1 PoC Analysis EPSS 0.00
Puneethreddyhc Online Shopping System Advanced - SQL Injection
A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
CWE-89 Jul 29, 2025
CVE-2025-41646 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.34
Software Package - Auth Bypass
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
CWE-704 Jun 06, 2025
CVE-2025-51869 7.5 HIGH 1 PoC Analysis EPSS 0.00
Liner <2025-06-03 - Info Disclosure
Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} endpoint.
CWE-639 Jul 21, 2025
CVE-2025-51868 7.5 HIGH SSVC PoC 1 PoC Analysis EPSS 0.00
Dippy <v2 - Info Disclosure
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
CWE-639 Jul 21, 2025
CVE-2025-51867 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Deepfiction AI - IDOR
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.
CWE-639 Jul 22, 2025
CVE-2025-51865 8.8 HIGH SSVC PoC 1 PoC Analysis EPSS 0.00
Ai2 Playground <2025-06-03 - Info Disclosure
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.
CWE-639 Jul 22, 2025
CVE-2025-51864 6.5 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
AIBOX LLM chat <2025-05-27 - XSS
A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.
CWE-79 Jul 22, 2025
CVE-2025-51863 6.1 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
ChatGPT Unli <2025-05-26 - XSS
Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.
CWE-79 Jul 22, 2025
CVE-2025-51862 6.1 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
TelegAI <2025-05-26 - Info Disclosure
Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An attacker can exploit this IDOR to tamper other users' conversation. Additionally, malicious contents and XSS payloads can be injected, leading to phishing attack, user spoofing and account hijacking via XSS.
CWE-79 Jul 22, 2025
CVE-2025-51860 6.1 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
TelegAI 2025-05-26 - XSS
Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container component. An attacker can achieve arbitrary client-side script execution by crafting an AI Character with SVG XSS payloads in either description, greeting, example dialog, or system prompt(instructing the LLM to embed XSS payload in its chat response). When a user interacts with such a malicious AI Character or just browse its profile, the script executes in the user's browser. Successful exploitation can lead to the theft of sensitive information, such as session tokens, potentially resulting in account hijacking.
CWE-79 Jul 22, 2025
CVE-2025-51859 6.5 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
Chaindesk <2025-05-26 - XSS
Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker can achieve arbitrary client-side script execution by crafting an AI agent whose system prompt instructs the underlying Large Language Model (LLM) to embed malicious script payloads (e.g., SVG-based XSS) into its chat responses. When a user interacts with such a malicious agent or accesses a direct link to a conversation containing an XSS payload, the script executes in the user's browser. Successful exploitation can lead to the theft of sensitive information, such as JWT session tokens, potentially resulting in account hijacking.
CWE-79 Jul 22, 2025
CVE-2025-51858 6.1 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
ChatPlayground.ai <2025-05-24 - XSS
Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.
CWE-79 Jul 22, 2025