Latest Vulnerabilities with Public Exploits

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
53,634 results Clear all
CVE-2025-65856 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
Xiongmaitech Xm530v200 X6-weq 8M Firmware - Missing Authentication
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
CWE-306 Dec 22, 2025
CVE-2025-61155 5.5 MEDIUM EXPLOITED RANSOMWARE 1 PoC Analysis EPSS 0.00
GameDriverX64.sys <7.23.4.7 - Privilege Escalation
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper authentication or access validation, allowing the attacker to terminate arbitrary processes, including critical system and security services, without requiring administrative privileges.
CWE-400 Oct 28, 2025
CVE-2025-6202 HIGH 1 PoC Analysis EPSS 0.00
SK Hynix DDR5 - Memory Corruption
Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity and the system's security. This issue affects DDR5: DIMMs produced from 2021-1 until 2024-12.
CWE-404 Sep 15, 2025
CVE-2025-70886 7.5 HIGH 1 PoC Analysis EPSS 0.00
Halo <2.22.4 - DoS
An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
CWE-400 Feb 12, 2026
CVE-2025-9208 5.4 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
OpenText Web Site Management Server 16.7.X-16.8.1 - XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data. This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.
CWE-79 Feb 19, 2026
CVE-2025-13672 5.4 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
OpenText Web Site Management 16.7.0-16.7.1 - XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side. This issue affects Web Site Management Server: 16.7.0, 16.7.1.
CWE-79 Feb 19, 2026
CVE-2025-13671 6.5 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
OpenText Web Site Management Server 16.7.0-16.7.1 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously. This issue affects Web Site Management Server: 16.7.0, 16.7.1.
CWE-352 Feb 19, 2026
CVE-2025-36248 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
IBM Copy Services Manager < 6.3.14 - XSS
IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CWE-79 Sep 19, 2025
CVE-2025-69015 3.8 LOW 1 PoC Analysis EPSS 0.00
Automattic Crowdsignal Forms <1.7.3 - Info Disclosure
Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2.
CWE-862 Dec 30, 2025
CVE-2025-13543 8.8 HIGH 2 PoCs Analysis EPSS 0.00
PostGallery plugin <1.12.5 - File Upload
The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434 Dec 04, 2025
CVE-2025-2301 4.4 MEDIUM 1 PoC Analysis EPSS 0.00
Akbim Software Online Exam Registration <14.03.2025 - Auth Bypass
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers.This issue affects Online Exam Registration: before 14.03.2025.
CWE-639 Jul 21, 2025
CVE-2025-68723 9.0 CRITICAL 1 PoC Analysis EPSS 0.00
Axigen Mail Server <10.5.57 - XSS
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File name parameter in the WebMail Listeners SSL settings. Attackers can inject malicious JavaScript payloads that execute in administrators' browsers when they access affected pages or features, enabling privilege escalation attacks where low-privileged admins can force high-privileged admins to perform unauthorized actions.
CWE-79 Feb 05, 2026
CVE-2025-68722 8.8 HIGH 1 PoC Analysis EPSS 0.00
Axigen Mail Server <10.5.57, 10.6.x <10.6.26 - CSRF
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the _s parameter immediately after administrator authentication. Attackers can craft malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction, including creating rogue administrator accounts or modifying critical server configurations.
CWE-352 Feb 05, 2026
CVE-2025-55853 9.1 CRITICAL 1 PoC 1 Writeup Analysis EPSS 0.00
SoftVision webPDF <10.0.2 - SSRF
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI).
CWE-918 Feb 19, 2026
CVE-2025-40778 8.6 HIGH 3 PoCs Analysis EPSS 0.00
BIND <9.21 - Info Disclosure
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
CWE-349 Oct 22, 2025
CVE-2025-69906 8.8 HIGH 1 PoC Analysis EPSS 0.00
Monstra Cms - Unrestricted File Upload
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.
CWE-434 Feb 05, 2026
CVE-2025-10380 8.8 HIGH 1 PoC Analysis EPSS 0.00
Advanced Views - Server-Side Template Injection
The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to execute arbitrary PHP code and commands on the server.
CWE-1336 Sep 23, 2025
CVE-2025-58981 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Equalize Digital Accessibility Checker <1.31.0 - Info Disclosure
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.
CWE-862 Sep 09, 2025
CVE-2025-58976 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Equalize Digital Accessibility Checker <1.31.0 - Info Disclosure
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.
CWE-862 Sep 09, 2025
CVE-2025-30975 7.5 HIGH 1 PoC Analysis EPSS 0.00
SaifuMak Add Custom Codes <4.80 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80.
CWE-94 Aug 20, 2025