Latest Vulnerabilities with Public Exploits
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,633 results
Clear all
CVE-2025-69565
9.8
CRITICAL
1 PoC
EPSS 0.00
Fabian Mobile Shop Management System - Unrestricted File Upload
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
CWE-434
Jan 27, 2026
CVE-2025-70986
7.5
HIGH
1 PoC
EPSS 0.00
Ruoyi - Improper Access Control
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.
CWE-284
Jan 23, 2026
CVE-2025-70985
9.1
CRITICAL
1 PoC
EPSS 0.00
Ruoyi - Improper Access Control
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
CWE-284
Jan 23, 2026
CVE-2025-9647
4.3
MEDIUM
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
CWE-94
Aug 29, 2025
CVE-2025-9433
4.3
MEDIUM
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
CWE-94
Aug 26, 2025
CVE-2025-9432
4.3
MEDIUM
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-94
Aug 26, 2025
CVE-2025-9431
4.3
MEDIUM
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
CWE-94
Aug 26, 2025
CVE-2025-9430
2.4
LOW
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
CWE-94
Aug 26, 2025
CVE-2025-9429
3.5
LOW
2 PoCs
EPSS 0.00
mtons mblog <3.5.0 - XSS
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
CWE-94
Aug 26, 2025
CVE-2025-9407
3.5
LOW
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - XSS
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.
CWE-94
Aug 25, 2025
CVE-2025-9005
3.7
LOW
1 PoC
EPSS 0.00
Mtons Mblog < 3.5.0 - Information Disclosure
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
CWE-209
Aug 15, 2025
CVE-2025-9004
3.7
LOW
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - Auth Bypass
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CWE-799
Aug 15, 2025
CVE-2025-8992
4.3
MEDIUM
1 PoC
EPSS 0.00
Mtons Mblog < 3.5.0 - Missing Authorization
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-862
Aug 15, 2025
CVE-2025-8927
3.7
LOW
1 PoC
EPSS 0.00
mtons mblog <3.5.0 - Auth Bypass
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CWE-799
Aug 13, 2025
CVE-2025-8815
7.3
HIGH
1 PoC
EPSS 0.00
Morning - Path Traversal
A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown function of the file /index of the component Shiro Configuration. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CWE-22
Aug 10, 2025
CVE-2025-8752
7.3
HIGH
1 PoC
EPSS 0.01
Xuanshao Spring-shiro-training - Command Injection
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-74
Aug 09, 2025
CVE-2025-8228
6.3
MEDIUM
1 PoC
EPSS 0.00
Chancms < 3.1.3 - SSRF
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the file /cms/collect/getPages. The manipulation of the argument targetUrl leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.3 is able to address this issue. It is recommended to upgrade the affected component.
CWE-918
Jul 27, 2025
CVE-2025-8227
6.3
MEDIUM
2 PoCs
EPSS 0.00
Chancms < 3.1.3 - Insecure Deserialization
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /collect/getArticle. The manipulation of the argument taskUrl leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.3 is able to address this issue. The patch is named 33d9bb464353015aaaba84e27638ac9a3912795d. It is recommended to upgrade the affected component.
CWE-502
Jul 27, 2025
CVE-2025-8226
4.3
MEDIUM
1 PoC
EPSS 0.00
Chancms < 3.1.3 - Information Disclosure
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. The manipulation of the argument accessKey/secretKey leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.3 is able to address this issue. It is recommended to upgrade the affected component.
CWE-284
Jul 27, 2025
CVE-2025-8163
6.3
MEDIUM
1 PoC
EPSS 0.00
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/role/list. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-74
Jul 25, 2025