Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
53,633 results Clear all
CVE-2025-5383 2.4 LOW 1 PoC EPSS 0.00
Wanglongcn Yifang < 2.0.2 - Code Injection
A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-94 May 31, 2025
CVE-2025-5381 2.7 LOW 1 PoC EPSS 0.01
Wanglongcn Yifang < 2.0.2 - Path Traversal
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component Admin Panel. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-22 May 31, 2025
CVE-2025-5380 6.3 MEDIUM 1 PoC EPSS 0.00
XueShengZhuSu <4d3f0ada - Path Traversal
A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of the file /upload/ of the component Image File Upload. The manipulation of the argument File leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
CWE-22 May 31, 2025
CVE-2025-5149 5.6 MEDIUM 1 PoC EPSS 0.01
Wcms < 8.3.11 - Authentication Bypass
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-287 May 25, 2025
CVE-2025-5033 4.3 MEDIUM 1 PoC EPSS 0.00
TeaCMS 2.0.2 - CSRF
A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-862 May 21, 2025
CVE-2025-5013 4.3 MEDIUM 1 PoC EPSS 0.00
HkCms <2.3.2.240702 - XSS
A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-94 May 21, 2025
CVE-2025-29691 6.1 MEDIUM 1 PoC EPSS 0.00
Hailey888 OA System < 2025-01-01 - XSS
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.
CWE-79 May 14, 2025
CVE-2025-29690 6.1 MEDIUM 1 PoC EPSS 0.00
Hailey888 OA System < 2025-01-01 - XSS
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.
CWE-79 May 14, 2025
CVE-2025-29689 6.1 MEDIUM 1 PoC EPSS 0.00
Hailey888 OA System < 2025-01-01 - XSS
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.
CWE-79 May 14, 2025
CVE-2025-29688 6.1 MEDIUM 1 PoC EPSS 0.00
Hailey888 OA System < 2025-01-01 - XSS
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.
CWE-79 May 14, 2025
CVE-2025-29686 6.1 MEDIUM 1 PoC EPSS 0.00
Hailey888 OA System < 2025-01-01 - XSS
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.
CWE-79 May 14, 2025
CVE-2025-45887 9.1 CRITICAL 1 PoC EPSS 0.00
Wanglongcn Yifang - SSRF
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
CWE-918 May 09, 2025
CVE-2025-4291 6.3 MEDIUM 1 PoC EPSS 0.00
IdeaCMS <1.6 - Unrestricted Upload
A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-284 May 05, 2025
CVE-2025-45239 5.3 MEDIUM 1 PoC EPSS 0.00
Qianfox Foxcms - Path Traversal
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
CWE-22 May 05, 2025
CVE-2025-3977 4.3 MEDIUM 1 PoC EPSS 0.00
iteachyou Dreamer CMS <4.1.3 - Info Disclosure
A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/attachment/download of the component Attachment Handler. The manipulation of the argument ID leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-266 Apr 27, 2025
CVE-2025-28099 4.3 MEDIUM 1 PoC EPSS 0.00
Fumiao Opencms - Path Traversal
opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,
CWE-22 Apr 21, 2025
CVE-2025-29287 9.8 CRITICAL 1 PoC EPSS 0.02
Mingsoft Mcms < 5.4.4 - Unrestricted File Upload
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
CWE-434 Apr 21, 2025
CVE-2025-3393 3.5 LOW 1 PoC EPSS 0.00
mrcen springboot-ucan-admin - XSS
A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index of the component Personal Settings Interface. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
CWE-79 Apr 08, 2025
CVE-2025-3392 3.5 LOW 1 PoC EPSS 0.00
hailey888 oa_system <2025.01.01 - XSS
A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/mail/MailController.java of the component Backend. The manipulation of the argument MailNumberId leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-94 Apr 08, 2025
CVE-2025-3391 3.5 LOW 1 PoC EPSS 0.00
hailey888 oa_system <2025.01.01 - XSS
A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/oass/controller/address/AddrController. java of the component Backend. The manipulation of the argument outtype leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
CWE-94 Apr 08, 2025