Latest Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,701 results
Clear all
CVE-2025-46171
5.4
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Vbulletin - Denial of Service
vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.
CWE-400
Jul 23, 2025
CVE-2025-5222
7.0
HIGH
1 PoC
Analysis
EPSS 0.00
International Components For Unicode < 77.1 - Buffer Overflow
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
CWE-120
May 27, 2025
CVE-2025-45960
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Tawk.to < 1.6.1 - XSS
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding
CWE-79
Jul 25, 2025
CVE-2025-47165
7.8
HIGH
EXPLOITED
1 PoC
Analysis
EPSS 0.01
Microsoft 365 Apps < 16.0.10417.20018 - Use After Free
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-416
Jun 10, 2025
CVE-2025-5640
3.3
LOW
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
PX4-Autopilot 1.12.3 - Buffer Overflow
A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the file mavlink_receiver.cpp of the component TRAJECTORY_REPRESENTATION_WAYPOINTS Message Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CWE-119
Jun 05, 2025
CVE-2025-30712
8.1
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Oracle VM Virtualbox - Integer Overflow
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L).
CWE-190
Apr 15, 2025
CVE-2025-47577
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.01
TemplateInvaders TI WooCommerce Wishlist <2.10.0 - Code Injection
Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.9.2.
CWE-434
May 19, 2025
CVE-2025-27558
9.1
CRITICAL
1 PoC
Analysis
EPSS 0.00
IEEE P802.11-REVme - FragAttacks
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.
CWE-345
May 21, 2025
CVE-2025-0054
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
SAP NetWeaver Application Server Java - XSS
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.
CWE-79
Feb 11, 2025
CVE-2025-45467
7.1
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Unitree Go1 Firmware - Incorrect Default Permissions
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.
CWE-276
Jul 25, 2025
CVE-2025-45466
8.8
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Unitree Go1 Firmware - Hard-coded Credentials
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
CWE-798
Jul 25, 2025
CVE-2025-48461
5.0
MEDIUM
1 PoC
Analysis
EPSS 0.00
Unspecified - Info Disclosure
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
CWE-341
Jun 24, 2025
CVE-2025-48988
7.5
HIGH
2 PoCs
Analysis
EPSS 0.01
Apache Tomcat - Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
CWE-770
Jun 16, 2025
CVE-2025-48976
7.5
HIGH
2 PoCs
Analysis
EPSS 0.01
Apache Commons FileUpload <1.6-2.0.0-M4 - DoS
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
CWE-770
Jun 16, 2025
CVE-2025-44203
7.5
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Digitaldruid Hoteldruid - Error Information Exposure
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
CWE-400
Jun 20, 2025
CVE-2025-4275
7.8
HIGH
1 PoC
Analysis
EPSS 0.00
UEFI - Code Injection
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Jun 11, 2025
CVE-2025-36041
4.7
MEDIUM
1 PoC
Analysis
EPSS 0.00
IBM MQ Operator < 2.0.29 - Improper Certificate Validation
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.
CWE-295
Jun 15, 2025
CVE-2025-47957
8.4
HIGH
1 PoC
Analysis
EPSS 0.01
Microsoft 365 Apps - Use After Free
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CWE-416
Jun 10, 2025
CVE-2025-6335
4.7
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.01
DedeCMS <5.7.2 - Command Injection
A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-74
Jun 20, 2025
CVE-2025-26443
7.3
HIGH
1 PoC
Analysis
EPSS 0.00
Android - Privilege Escalation
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CWE-693
Sep 04, 2025