Latest Vulnerabilities with Public Exploits
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,701 results
Clear all
CVE-2025-48466
8.1
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Modbus TCP - RCE
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.
CWE-863
Jun 24, 2025
CVE-2025-32710
8.1
HIGH
1 PoC
Analysis
EPSS 0.01
Microsoft Windows Server 2008 < 10.0.14393.8066 - Race Condition
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CWE-362
Jun 10, 2025
CVE-2025-49125
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Apache Tomcat < 9.0.106 - Authentication Bypass
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
CWE-288
Jun 16, 2025
CVE-2025-46157
9.9
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.01
Efrotech Timetrax - Unrestricted File Upload
An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form
CWE-434
Jun 18, 2025
CVE-2025-6220
7.2
HIGH
1 PoC
Analysis
EPSS 0.04
Ultra Addons for Contact Form 7 <3.5.12 - File Upload
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434
Jun 18, 2025
CVE-2025-45619
6.5
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Averusa Ptc310uv2 Firmware - Command Injection
An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function
CWE-77
Jul 30, 2025
CVE-2025-45620
8.1
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Averusa Ptc310uv2 Firmware - Information Disclosure
An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
CWE-200
Jul 30, 2025
CVE-2025-5964
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
M-files Server < 24.8.13981.16 - Path Traversal
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
CWE-22
Jun 15, 2025
CVE-2025-66555
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
AirKeyboard iOS App 1.0.5 - RCE
AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.
CWE-306
Dec 04, 2025
CVE-2025-37928
7.8
HIGH
1 PoC
Analysis
EPSS 0.00
Linux kernel - Use After Free
In the Linux kernel, the following vulnerability has been resolved:
dm-bufio: don't schedule in atomic context
A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and
try_verify_in_tasklet are enabled.
[ 129.444685][ T934] BUG: sleeping function called from invalid context at drivers/md/dm-bufio.c:2421
[ 129.444723][ T934] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 934, name: kworker/1:4
[ 129.444740][ T934] preempt_count: 201, expected: 0
[ 129.444756][ T934] RCU nest depth: 0, expected: 0
[ 129.444781][ T934] Preemption disabled at:
[ 129.444789][ T934] [<ffffffd816231900>] shrink_work+0x21c/0x248
[ 129.445167][ T934] kernel BUG at kernel/sched/walt/walt_debug.c:16!
[ 129.445183][ T934] Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
[ 129.445204][ T934] Skip md ftrace buffer dump for: 0x1609e0
[ 129.447348][ T934] CPU: 1 PID: 934 Comm: kworker/1:4 Tainted: G W OE 6.6.56-android15-8-o-g6f82312b30b9-debug #1 1400000003000000474e5500b3187743670464e8
[ 129.447362][ T934] Hardware name: Qualcomm Technologies, Inc. Parrot QRD, Alpha-M (DT)
[ 129.447373][ T934] Workqueue: dm_bufio_cache shrink_work
[ 129.447394][ T934] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 129.447406][ T934] pc : android_rvh_schedule_bug+0x0/0x8 [sched_walt_debug]
[ 129.447435][ T934] lr : __traceiter_android_rvh_schedule_bug+0x44/0x6c
[ 129.447451][ T934] sp : ffffffc0843dbc90
[ 129.447459][ T934] x29: ffffffc0843dbc90 x28: ffffffffffffffff x27: 0000000000000c8b
[ 129.447479][ T934] x26: 0000000000000040 x25: ffffff804b3d6260 x24: ffffffd816232b68
[ 129.447497][ T934] x23: ffffff805171c5b4 x22: 0000000000000000 x21: ffffffd816231900
[ 129.447517][ T934] x20: ffffff80306ba898 x19: 0000000000000000 x18: ffffffc084159030
[ 129.447535][ T934] x17: 00000000d2b5dd1f x16: 00000000d2b5dd1f x15: ffffffd816720358
[ 129.447554][ T934] x14: 0000000000000004 x13: ffffff89ef978000 x12: 0000000000000003
[ 129.447572][ T934] x11: ffffffd817a823c4 x10: 0000000000000202 x9 : 7e779c5735de9400
[ 129.447591][ T934] x8 : ffffffd81560d004 x7 : 205b5d3938373434 x6 : ffffffd8167397c8
[ 129.447610][ T934] x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffffffc0843db9e0
[ 129.447629][ T934] x2 : 0000000000002f15 x1 : 0000000000000000 x0 : 0000000000000000
[ 129.447647][ T934] Call trace:
[ 129.447655][ T934] android_rvh_schedule_bug+0x0/0x8 [sched_walt_debug 1400000003000000474e550080cce8a8a78606b6]
[ 129.447681][ T934] __might_resched+0x190/0x1a8
[ 129.447694][ T934] shrink_work+0x180/0x248
[ 129.447706][ T934] process_one_work+0x260/0x624
[ 129.447718][ T934] worker_thread+0x28c/0x454
[ 129.447729][ T934] kthread+0x118/0x158
[ 129.447742][ T934] ret_from_fork+0x10/0x20
[ 129.447761][ T934] Code: ???????? ???????? ???????? d2b5dd1f (d4210000)
[ 129.447772][ T934] ---[ end trace 0000000000000000 ]---
dm_bufio_lock will call spin_lock_bh when try_verify_in_tasklet
is enabled, and __scan will be called in atomic context.
May 20, 2025
CVE-2025-4255
7.3
HIGH
1 PoC
Analysis
EPSS 0.04
PCMan FTP Server 2.0.7 - Buffer Overflow
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-119
May 05, 2025
CVE-2025-27751
7.8
HIGH
1 PoC
Analysis
EPSS 0.01
Microsoft 365 Apps - Use After Free
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CWE-416
Apr 08, 2025
CVE-2025-1219
5.3
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
PHP <8.1.32, <8.2.28, <8.3.19, <8.4.5 - Info Disclosure
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.
CWE-1116
Mar 30, 2025
CVE-2025-5815
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
WordPress Traffic Monitor <3.2.2 - Info Disclosure
The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.
CWE-862
Jun 13, 2025
CVE-2025-21420
7.8
HIGH
4 PoCs
Analysis
EPSS 0.41
Microsoft Windows 10 1507 < 10.0.10240.20915 - Symlink Following
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
CWE-59
Feb 11, 2025
CVE-2025-24035
8.1
HIGH
1 PoC
Analysis
EPSS 0.00
Windows Remote Desktop Services - Memory Corruption
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CWE-591
Mar 11, 2025
CVE-2025-4601
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
RH - Real Estate WordPress Theme <4.4.0 - Privilege Escalation
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to set their role to that of an administrator. The vulnerability was partially patched in version 4.4.0, and fully patched in version 4.4.1.
CWE-269
Jun 10, 2025
CVE-2025-46178
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Vishalmathur Cloudclassroom-php Project - XSS
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.
CWE-79
Jun 09, 2025
CVE-2025-39507
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Nasa Core <6.3.2 - Code Injection
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclusion.This issue affects Nasa Core: from n/a through < 6.4.4.
CWE-829
May 16, 2025
CVE-2025-24076
7.3
HIGH
2 PoCs
Analysis
EPSS 0.03
Microsoft Windows 11 22h2 < 10.0.22621.5039 - Improper Access Control
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CWE-284
Mar 11, 2025