Latest Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,633 results
Clear all
CVE-2025-25585
7.3
HIGH
1 PoC
EPSS 0.00
R1bbit Yimioa < 2024.07.04 - Improper Access Control
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
CWE-284
Mar 18, 2025
CVE-2025-25580
6.1
MEDIUM
1 PoC
EPSS 0.00
R1bbit Yimioa < 2024.07.04 - SQL Injection
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
CWE-89
Mar 18, 2025
CVE-2025-2420
4.3
MEDIUM
1 PoC
EPSS 0.00
猫宁i Morning - CSRF
A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
CWE-352
Mar 17, 2025
CVE-2025-26047
5.1
MEDIUM
1 PoC
EPSS 0.00
Olajowon Loggrove - SQL Injection
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
CWE-89
Feb 28, 2025
CVE-2025-1745
4.3
MEDIUM
1 PoC
EPSS 0.00
Pb-cms - Missing Authorization
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-862
Feb 27, 2025
CVE-2025-26014
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Olajowon Loggrove - Code Injection
A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.
CWE-94
Feb 21, 2025
CVE-2025-26013
8.2
HIGH
1 PoC
EPSS 0.00
Loggrove 1.0 - Info Disclosure
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
CWE-540
Feb 21, 2025
CVE-2025-1332
2.4
LOW
1 PoC
EPSS 0.00
Xjd2020 Fastcms < 0.1.5 - Code Injection
A vulnerability has been found in FastCMS up to 0.1.5 and classified as problematic. This vulnerability affects unknown code of the file /fastcms.html#/template/menu of the component Template Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-94
Feb 16, 2025
CVE-2025-1229
6.3
MEDIUM
1 PoC
EPSS 0.00
Loggrove - Code Injection
A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability is an unknown functionality of the file /read/?page=1&logfile=eee&match=. The manipulation of the argument path leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
CWE-77
Feb 12, 2025
CVE-2025-1228
4.3
MEDIUM
1 PoC
EPSS 0.00
Loggrove <e428fac38cc480f011afcb1d8ce6c2bad378ddd6 - Path Traversal
A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected is an unknown function of the file /read/?page=1&logfile=LOG_Monitor of the component Logfile Update Handler. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-22
Feb 12, 2025
CVE-2025-1227
6.3
MEDIUM
1 PoC
EPSS 0.00
ywoa <2024.07.03 - SQL Injection
A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
CWE-74
Feb 12, 2025
CVE-2025-1226
5.3
MEDIUM
1 PoC
EPSS 0.00
ywoa <2024.07.03 - Auth Bypass
A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
CWE-266
Feb 12, 2025
CVE-2025-1225
6.3
MEDIUM
1 PoC
EPSS 0.00
ywoa <2024.07.03 - XML External Entity Reference
A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
CWE-611
Feb 12, 2025
CVE-2025-1224
6.3
MEDIUM
1 PoC
EPSS 0.00
ywoa <2024.07.03 - SQL Injection
A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
CWE-74
Feb 12, 2025
CVE-2025-1216
6.3
MEDIUM
1 PoC
EPSS 0.00
ywoa <2024.07.03 - SQL Injection
A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
CWE-74
Feb 12, 2025
CVE-2025-1113
6.3
MEDIUM
1 PoC
EPSS 0.00
Taisan Tarzan-cms - Insecure Deserialization
A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-502
Feb 07, 2025
CVE-2025-0708
3.5
LOW
1 PoC
EPSS 0.00
fumiao opencms 2.2 - XSS
A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/model/addOrUpdate of the component Add Model Management Page. The manipulation of the argument 模板前缀 leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-94
Jan 24, 2025
CVE-2025-69564
9.8
CRITICAL
1 PoC
EPSS 0.00
Fabian Mobile Shop Management System - Code Injection
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters.
CWE-94
Jan 27, 2026
CVE-2025-69563
9.8
CRITICAL
1 PoC
EPSS 0.00
Fabian Mobile Shop Management System - SQL Injection
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.
CWE-89
Jan 27, 2026
CVE-2025-69562
9.8
CRITICAL
1 PoC
EPSS 0.00
Fabian Mobile Shop Management System - SQL Injection
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.
CWE-89
Jan 27, 2026