Latest Vulnerabilities with Public Exploits
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,634 results
Clear all
CVE-2025-65856
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
Xiongmaitech Xm530v200 X6-weq 8M Firmware - Missing Authentication
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
CWE-306
Dec 22, 2025
CVE-2025-61155
5.5
MEDIUM
EXPLOITED
RANSOMWARE
1 PoC
Analysis
EPSS 0.00
GameDriverX64.sys <7.23.4.7 - Privilege Escalation
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper authentication or access validation, allowing the attacker to terminate arbitrary processes, including critical system and security services, without requiring administrative privileges.
CWE-400
Oct 28, 2025
CVE-2025-6202
HIGH
1 PoC
Analysis
EPSS 0.00
SK Hynix DDR5 - Memory Corruption
Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity and the system's security. This issue affects DDR5: DIMMs produced from 2021-1 until 2024-12.
CWE-404
Sep 15, 2025
CVE-2025-70886
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Halo <2.22.4 - DoS
An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
CWE-400
Feb 12, 2026
CVE-2025-9208
5.4
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
OpenText Web Site Management Server 16.7.X-16.8.1 - XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data.
This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.
CWE-79
Feb 19, 2026
CVE-2025-13672
5.4
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
OpenText Web Site Management 16.7.0-16.7.1 - XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
CWE-79
Feb 19, 2026
CVE-2025-13671
6.5
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
OpenText Web Site Management Server 16.7.0-16.7.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
CWE-352
Feb 19, 2026
CVE-2025-36248
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
IBM Copy Services Manager < 6.3.14 - XSS
IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CWE-79
Sep 19, 2025
CVE-2025-69015
3.8
LOW
1 PoC
Analysis
EPSS 0.00
Automattic Crowdsignal Forms <1.7.3 - Info Disclosure
Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2.
CWE-862
Dec 30, 2025
CVE-2025-13543
8.8
HIGH
2 PoCs
Analysis
EPSS 0.00
PostGallery plugin <1.12.5 - File Upload
The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434
Dec 04, 2025
CVE-2025-2301
4.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Akbim Software Online Exam Registration <14.03.2025 - Auth Bypass
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers.This issue affects Online Exam Registration: before 14.03.2025.
CWE-639
Jul 21, 2025
CVE-2025-68723
9.0
CRITICAL
1 PoC
Analysis
EPSS 0.00
Axigen Mail Server <10.5.57 - XSS
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File name parameter in the WebMail Listeners SSL settings. Attackers can inject malicious JavaScript payloads that execute in administrators' browsers when they access affected pages or features, enabling privilege escalation attacks where low-privileged admins can force high-privileged admins to perform unauthorized actions.
CWE-79
Feb 05, 2026
CVE-2025-68722
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Axigen Mail Server <10.5.57, 10.6.x <10.6.26 - CSRF
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the _s parameter immediately after administrator authentication. Attackers can craft malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction, including creating rogue administrator accounts or modifying critical server configurations.
CWE-352
Feb 05, 2026
CVE-2025-55853
9.1
CRITICAL
1 PoC
1 Writeup
Analysis
EPSS 0.00
SoftVision webPDF <10.0.2 - SSRF
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI).
CWE-918
Feb 19, 2026
CVE-2025-40778
8.6
HIGH
3 PoCs
Analysis
EPSS 0.00
BIND <9.21 - Info Disclosure
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
CWE-349
Oct 22, 2025
CVE-2025-69906
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Monstra Cms - Unrestricted File Upload
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.
CWE-434
Feb 05, 2026
CVE-2025-10380
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Advanced Views - Server-Side Template Injection
The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to execute arbitrary PHP code and commands on the server.
CWE-1336
Sep 23, 2025
CVE-2025-58981
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Equalize Digital Accessibility Checker <1.31.0 - Info Disclosure
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.
CWE-862
Sep 09, 2025
CVE-2025-58976
4.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
Equalize Digital Accessibility Checker <1.31.0 - Info Disclosure
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.
CWE-862
Sep 09, 2025
CVE-2025-30975
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
SaifuMak Add Custom Codes <4.80 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80.
CWE-94
Aug 20, 2025