Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,876 CVEs tracked 53,708 with exploits 4,860 exploited in wild 1,585 CISA KEV 4,078 Nuclei templates 53,663 vendors 43,954 researchers
53,708 results Clear all
CVE-2024-2827 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Lakernote Easyadmin < 2024-03-15 - SSRF
A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file /ureport/designer/saveReportFile. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257717 was assigned to this vulnerability.
CWE-918 Mar 22, 2024
CVE-2024-2826 6.3 MEDIUM 1 PoC EPSS 0.00
Lakernote Easyadmin < 2024-03-15 - XXE
A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257716.
CWE-611 Mar 22, 2024
CVE-2024-2825 6.3 MEDIUM 1 PoC EPSS 0.00
Lakernote Easyadmin < 2024-03-15 - Path Traversal
A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation of the argument file leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257715.
CWE-24 Mar 22, 2024
CVE-2024-29474 5.4 MEDIUM SSVC PoC 1 PoC EPSS 0.01
OneBlog v2.3.4 - XSS
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.
CWE-79 Mar 20, 2024
CVE-2024-29473 6.1 MEDIUM 1 PoC EPSS 0.00
OneBlog v2.3.4 - XSS
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.
CWE-79 Mar 20, 2024
CVE-2024-29472 5.4 MEDIUM 1 PoC EPSS 0.00
OneBlog v2.3.4 - XSS
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.
CWE-79 Mar 20, 2024
CVE-2024-29471 5.4 MEDIUM SSVC PoC 1 PoC EPSS 0.00
OneBlog v2.3.4 - XSS
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.
CWE-79 Mar 20, 2024
CVE-2024-29470 6.1 MEDIUM 1 PoC EPSS 0.00
OneBlog v2.3.4 - XSS
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.
CWE-79 Mar 20, 2024
CVE-2024-29469 6.1 MEDIUM SSVC PoC 1 PoC EPSS 0.00
OneBlog v2.3.4 - XSS
A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module.
CWE-79 Mar 20, 2024
CVE-2024-28418 6.5 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Webedition Cms - Unrestricted File Upload
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CWE-434 Mar 14, 2024
CVE-2024-28417 6.3 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Webedition Cms - Basic XSS
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CWE-80 Mar 14, 2024
CVE-2024-57521 10.0 CRITICAL SSVC PoC 2 PoCs Analysis EPSS 0.01
Ruoyi < 4.7.9 - SQL Injection
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
CWE-89 Dec 23, 2025
CVE-2024-52786 9.8 CRITICAL SSVC PoC 1 PoC EPSS 0.01
Anji-plus AJ-Report <1.4.2 - Auth Bypass
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.
CWE-287 Aug 22, 2025
CVE-2024-50645 9.8 CRITICAL SSVC PoC 1 PoC 1 Writeup Analysis EPSS 0.00
MallChat v1.0-SNAPSHOT - Auth Bypass
MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
CWE-287 Aug 22, 2025
CVE-2024-50644 9.8 CRITICAL SSVC PoC 1 PoC 1 Writeup Analysis EPSS 0.00
zhisheng17 blog 3.0.1-SNAPSHOT - Auth Bypass
zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
CWE-287 Aug 22, 2025
CVE-2024-46089 6.3 MEDIUM SSVC PoC 1 PoC 1 Writeup Analysis EPSS 0.02
74cms < 3.33.0 - Command Injection
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
CWE-77 Apr 18, 2025
CVE-2024-57407 7.3 HIGH SSVC PoC 1 PoC EPSS 0.00
Timo v2.0.3 - RCE
An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Feb 10, 2025
CVE-2024-54954 8.0 HIGH SSVC PoC 1 PoC EPSS 0.01
OneBlog v2.3.6 - Code Injection
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CWE-1336 Feb 10, 2025
CVE-2024-57776 4.6 MEDIUM SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025.01.01 - XSS
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CWE-79 Jan 16, 2025
CVE-2024-57775 8.8 HIGH SSVC PoC 1 PoC EPSS 0.00
Jfinaloa < 2025-01-01 - SQL Injection
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
CWE-89 Jan 16, 2025