Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,760 CVEs tracked 53,703 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 52,442 vendors 43,944 researchers
53,703 results Clear all
CVE-2025-25617 4.3 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
Unifiedtransform 2.X - Privilege Escalation
Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.
CWE-284 Mar 07, 2025
CVE-2025-25616 4.3 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.01
Changeweb Unifiedtransform - Improper Access Control
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
CWE-284 Mar 10, 2025
CVE-2025-25615 2.7 LOW SSVC PoC 1 PoC Analysis EPSS 0.00
Changeweb Unifiedtransform - Improper Access Control
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
CWE-284 Mar 10, 2025
CVE-2025-25614 8.8 HIGH SSVC PoC 1 PoC Analysis EPSS 0.00
Changeweb Unifiedtransform - Improper Access Control
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.
CWE-284 Mar 10, 2025
CVE-2025-26326 8.8 HIGH 1 PoC Analysis EPSS 0.03
NVDA Remote <2.6.4-2025.3.3 - RCE
A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept any password entered by the user and do not have an additional authentication or computer verification mechanism. Tests indicate that more than 1,000 systems use easy-to-guess passwords, many with less than 4 to 6 characters, including common sequences. This allows brute force attacks or trial-and-error attempts by malicious invaders. The vulnerability can be exploited by a remote attacker who knows or can guess the password used in the connection. As a result, the attacker gains complete access to the affected system and can execute commands, modify files, and compromise user security.
CWE-287 Feb 28, 2025
CVE-2025-25749 7.1 HIGH SSVC PoC 1 PoC Analysis EPSS 0.01
HotelDruid <3.0.7 - Info Disclosure
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
CWE-521 Mar 11, 2025
CVE-2025-25748 7.3 HIGH SSVC PoC 1 PoC Analysis EPSS 0.00
Digitaldruid Hoteldruid - CSRF
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.
CWE-352 Mar 11, 2025
CVE-2025-25747 5.4 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.02
Digitaldruid Hoteldruid - XSS
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
CWE-79 Mar 11, 2025
CVE-2025-24752 7.1 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.04
Wpdeveloper Essential Addons For Elementor < 6.0.15 - XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.14.
CWE-79 Apr 17, 2025
CVE-2025-26202 4.3 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
DZS Router - XSS
Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page
CWE-79 Mar 04, 2025
CVE-2025-25296 6.1 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.20
Label Studio <1.16.0 - XSS
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appropriately crafted `label_config` query parameter. By crafting a specially formatted XML label config with inline task data containing malicious HTML/JavaScript, an attacker can achieve Cross-Site Scripting (XSS). While the application has a Content Security Policy (CSP), it is only set in report-only mode, making it ineffective at preventing script execution. The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Version 1.16.0 contains a patch for the issue.
CWE-79 Feb 14, 2025
CVE-2025-24971 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.10
DumbDrop <commit 4ff8469d - Command Injection
DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the **Apprise Notification** enabled. This issue has been addressed in commit `4ff8469d` and all users are advised to patch. There are no known workarounds for this vulnerability.
CWE-78 Feb 04, 2025
CVE-2025-26318 5.8 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.02
TSplus Remote Access <17.30 - Info Disclosure
hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
CWE-201 Mar 04, 2025
CVE-2025-0364 9.8 CRITICAL SSVC PoC 1 PoC Analysis EPSS 0.22
BigAntSoft BigAnt Server <5.6.06 - RCE
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution.
CWE-288 Feb 04, 2025
CVE-2025-25461 5.4 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.00
Seeddms - XSS
A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this category, the payload is stored on the server and rendered without proper sanitization or output encoding. This results in the XSS payload executing in the browser of any user who views the document.
CWE-79 Feb 28, 2025
CVE-2025-26206 9.0 CRITICAL 1 PoC Analysis EPSS 0.00
Selldone Storefront - CSRF
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
CWE-352 Mar 03, 2025
CVE-2025-0924 7.2 HIGH 1 PoC Analysis EPSS 0.06
Melapress WP Activity Log < 5.3.0 - XSS
The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CWE-79 Feb 17, 2025
CVE-2025-25460 4.8 MEDIUM SSVC PoC 1 PoC Analysis EPSS 0.02
Flatpress - XSS
A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
CWE-79 Feb 24, 2025
CVE-2025-21401 4.5 MEDIUM 1 PoC Analysis EPSS 0.00
Microsoft Edge Chromium < 133.0.3065.69 - Open Redirect
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CWE-601 Feb 15, 2025
CVE-2025-25163 7.5 HIGH 2 PoCs Analysis EPSS 0.26
Zach Swetz Plugin A/B Image Optimizer <3.3 - Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimizer allows Path Traversal.This issue affects Plugin A/B Image Optimizer: from n/a through <= 3.3.
CWE-22 Feb 07, 2025