Latest Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,703 results
Clear all
CVE-2025-3568
3.5
LOW
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Webkul Krayin Crm - Code Injection
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.
CWE-94
Apr 14, 2025
CVE-2025-28009
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Appventure Dietiqa - SQL Injection
A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.
CWE-89
Apr 17, 2025
CVE-2025-34499
MEDIUM
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
AnyDesk 7.0.15,9.0.1 - Code Injection
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.
CWE-428
Dec 11, 2025
CVE-2025-24797
9.4
CRITICAL
1 PoC
Analysis
EPSS 0.02
Meshtastic Firmware < 2.6.2 - Memory Corruption
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentially resulting in remote code execution. This attack does not require authentication or user interaction, as long as the target device rebroadcasts packets on the default channel. This vulnerability fixed in 2.6.2.
CWE-119
Apr 15, 2025
CVE-2025-30967
9.6
CRITICAL
1 PoC
Analysis
EPSS 0.00
NotFound WPJobBoard - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard wpjobboard allows Upload a Web Shell to a Web Server.This issue affects WPJobBoard: from n/a through < 5.11.1.
CWE-352
Apr 15, 2025
CVE-2025-34504
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Kodcloud Kodexplorer - Open Redirect
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
CWE-601
Dec 11, 2025
CVE-2025-29722
6.3
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Yassmittal Commercify - CSRF
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
CWE-352
Apr 17, 2025
CVE-2025-22953
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Epicor Human Capital Management - SQL Injection
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.
CWE-89
Mar 28, 2025
CVE-2025-50251
9.1
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
makeplane plane <0.23.1 - SSRF
Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
CWE-918
Aug 13, 2025
CVE-2025-26865
3.5
LOW
1 PoC
Analysis
EPSS 0.00
Apache OFBiz <18.12.18 - Info Disclosure
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.
It's a regression between 18.12.17 and 18.12.18.
In case you use something like that, which is not recommended!
For security, only official releases should be used.
In other words, if you use 18.12.17 you are still safe.
The version 18.12.17 is not a affected.
But something between 18.12.17 and 18.12.18 is.
In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.
CWE-1336
Mar 10, 2025
CVE-2025-29705
4.3
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Tanghc Code-gen < 2.0.6 - Improper Access Control
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.
CWE-284
Apr 15, 2025
CVE-2025-22620
5.0
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.01
gitoxide <0.17.0 - Info Disclosure
gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a repository to be world-writable in some situations. This vulnerability is fixed in 0.17.0.
CWE-281
Jan 20, 2025
CVE-2025-29018
4.8
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Codeastro Internet Banking System - XSS
A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.
CWE-79
Apr 09, 2025
CVE-2025-29015
6.1
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Codeastro Internet Banking System - XSS
Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
CWE-79
Apr 17, 2025
CVE-2025-29017
8.8
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.02
Codeastro Internet Banking System - Unrestricted File Upload
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CWE-434
Apr 10, 2025
CVE-2025-29810
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Microsoft Windows 10 1507 < 10.0.10240.20978 - Improper Access Control
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
CWE-284
Apr 08, 2025
CVE-2025-32013
7.5
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Lnbits < 0.12.12 - SSRF
LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.
CWE-918
Apr 06, 2025
CVE-2025-27840
6.8
MEDIUM
3 PoCs
Analysis
EPSS 0.01
Espressif ESP32 - Info Disclosure
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
CWE-912
Mar 08, 2025
CVE-2025-66571
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
UNA CMS <14.0.0-RC4 - Code Injection
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated attackers to inject arbitrary PHP objects and potentially write and execute arbitrary PHP code.
CWE-502
Dec 04, 2025
CVE-2025-3047
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
SAM CLI <v1.133.0 - Privilege Escalation
When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container.
Users should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.
CWE-61
Mar 31, 2025