Latest Vulnerabilities with Public Exploits

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
53,633 results Clear all
CVE-2025-3390 3.5 LOW 1 PoC EPSS 0.00
hailey888 oa_system <2025.01.01 - XSS
A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CWE-94 Apr 08, 2025
CVE-2025-3389 3.5 LOW 1 PoC EPSS 0.00
hailey888 oa_system - XSS
A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
CWE-94 Apr 08, 2025
CVE-2025-3388 4.3 MEDIUM 1 PoC EPSS 0.00
hailey888 oa_system <2025.01.01 - XSS
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-94 Apr 07, 2025
CVE-2025-3387 3.5 LOW 1 PoC EPSS 0.00
renrenio renren-security <5.4.0 - XSS
A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-94 Apr 07, 2025
CVE-2025-3386 2.4 LOW 1 PoC EPSS 0.00
LinZhaoguan pb-cms 2.0 - XSS
A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-94 Apr 07, 2025
CVE-2025-3385 2.4 LOW 1 PoC EPSS 0.00
LinZhaoguan pb-cms 2.0 - XSS
A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Classification Management Page. The manipulation of the argument Classification name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-94 Apr 07, 2025
CVE-2025-3318 6.3 MEDIUM 1 PoC EPSS 0.00
Kenj_Frog 1.0 - SQL Injection
A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
CWE-74 Apr 06, 2025
CVE-2025-3317 4.3 MEDIUM 1 PoC EPSS 0.00
fumiao opencms - Path Traversal
A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CWE-22 Apr 06, 2025
CVE-2025-29504 7.8 HIGH 1 PoC EPSS 0.00
Huang-yk Student-manage - Incorrect Default Permissions
Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.
CWE-276 Apr 03, 2025
CVE-2025-3150 4.3 MEDIUM 1 PoC EPSS 0.00
Itning Student-homework-management-system - Missing Authorization
A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
CWE-862 Apr 03, 2025
CVE-2025-3149 2.4 LOW 1 PoC EPSS 0.00
Itning Student-homework-management-system < 1.2.7 - Code Injection
A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been classified as problematic. Affected is an unknown function of the file /shw_war/fileupload of the component Edit Job Page. The manipulation of the argument Course leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CWE-94 Apr 03, 2025
CVE-2025-2832 4.3 MEDIUM 1 PoC EPSS 0.00
Mingyuefusu Library Management System - Missing Authorization
A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-862 Mar 27, 2025
CVE-2025-2831 6.3 MEDIUM 1 PoC EPSS 0.00
Mingyuefusu Library Management System - Injection
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Mar 27, 2025
CVE-2025-2686 6.5 MEDIUM 1 PoC EPSS 0.00
mingyuefusu <d4836f6b49cd0ac79a4021b15ce99ff7229d4694 - Improper Ac...
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-266 Mar 24, 2025
CVE-2025-2617 2.4 LOW 1 PoC EPSS 0.00
yangyouwang crud - XSS
A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-79 Mar 22, 2025
CVE-2025-2616 2.4 LOW 1 PoC EPSS 0.00
yangyouwang crud - XSS
A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-79 Mar 22, 2025
CVE-2025-25589 8.1 HIGH 1 PoC EPSS 0.00
yimioa <2024.07.04 - RCE
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.
CWE-91 Mar 18, 2025
CVE-2025-25586 4.2 MEDIUM 1 PoC EPSS 0.00
R1bbit Yimioa < 2024-07-04 - Information Disclosure
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
CWE-538 Mar 18, 2025
CVE-2025-25582 6.1 MEDIUM 1 PoC EPSS 0.00
R1bbit Yimioa < 2024-07-04 - SQL Injection
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.
CWE-89 Mar 18, 2025
CVE-2025-25590 6.1 MEDIUM 1 PoC EPSS 0.00
R1bbit Yimioa < 2024.07.04 - SQL Injection
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
CWE-89 Mar 18, 2025