Latest Vulnerabilities with Public Exploits
Updated 6h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,639 results
Clear all
CVE-2025-15474
MEDIUM
1 PoC
Analysis
EPSS 0.00
AuntyFey Smart Combination Lock - DoS
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.
CWE-770
Jan 07, 2026
CVE-2025-10493
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.03
Chained Quiz <1.3.4 - Insecure Direct Object Reference
The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by manipulating the chained_completion_id cookie value, allowing them to alter quiz answers, scores, and results of any user. The vulnerability was partially patched in versions 1.3.4 and 1.3.5.
CWE-639
Sep 18, 2025
CVE-2025-68461
7.2
HIGH
KEV
2 PoCs
Analysis
EPSS 0.09
Roundcube Webmail < 1.5.12 - XSS
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
CWE-79
Dec 18, 2025
CVE-2025-66209
9.9
CRITICAL
1 PoC
Analysis
EPSS 0.00
Coolify <4.0.0-beta.451 - Command Injection
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.
CWE-78
Dec 23, 2025
CVE-2025-65270
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
Clincapture Captivate Electronic Data Capture - XSS
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
CWE-79
Dec 22, 2025
CVE-2025-45146
9.8
CRITICAL
1 PoC
2 Writeups
Analysis
EPSS 0.00
Codefuse Modelcache < 0.2.0 - Insecure Deserialization
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.
CWE-502
Aug 11, 2025
CVE-2025-13156
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Vitepos - Point of Sale (POS) for WooCommerce plugin <= 3.3.0 - Arbitrary File Upload
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the save_update_category_img() function accepting user-supplied file types without validation when processing category images. This makes it possible for authenticated attackers, with subscriber level access and above, to upload arbitrary files on the affected site's server which makes remote code execution possible.
CWE-434
Nov 21, 2025
CVE-2025-13339
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Hippoo Mobile App <1.7.1 - Path Traversal
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CWE-22
Dec 10, 2025
CVE-2025-13159
7.1
HIGH
1 PoC
Analysis
EPSS 0.00
Flo Forms <1.0.43 - XSS
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.0.43. This is due to the plugin allowing SVG file uploads via an unauthenticated AJAX endpoint (`flo_form_submit`) without proper file content validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when an administrator views the uploaded file in the WordPress admin interface, leading to potential full site compromise.
CWE-79
Nov 21, 2025
CVE-2025-12904
7.2
HIGH
1 PoC
Analysis
EPSS 0.00
H5PxAPIkatchu <0.4.17 - XSS
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CWE-79
Nov 14, 2025
CVE-2025-10142
4.9
MEDIUM
1 PoC
Analysis
EPSS 0.00
PagBank/PagSeguro Connect para WooCommerce <4.44.3 - SQL Injection
The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 4.44.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Sep 10, 2025
CVE-2025-10175
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
WP Links Page <4.9.6 - SQL Injection
The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Oct 11, 2025
CVE-2025-8091
4.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
EventON Lite <2.4.6 - Info Disclosure
The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
CWE-200
Aug 15, 2025
CVE-2025-9886
4.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
Trinity Audio - Text to Speech AI <5.20.2 - CSRF
The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.20.2. This is due to missing or incorrect nonce validation in the '/admin/inc/post-management.php' file. This makes it possible for unauthenticated attackers to activate/deactivate posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352
Oct 04, 2025
CVE-2025-12139
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.16
Google Drive WordPress Plugin <1.5.3 - Info Disclosure
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.
CWE-200
Nov 05, 2025
CVE-2025-65857
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Xiongmai XM530 IP cameras - Info Disclosure
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
CWE-359
Dec 22, 2025
CVE-2025-67586
4.7
MEDIUM
1 PoC
Analysis
EPSS 0.01
Highlight and Share <5.2.0 - RCE
Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0.
CWE-862
Dec 09, 2025
CVE-2025-63664
7.5
HIGH
1 PoC
1 Writeup
Analysis
EPSS 0.00
GT Edge AI Platform <2.0.10-dev - Info Disclosure
Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.
CWE-284
Dec 22, 2025
CVE-2025-63663
7.5
HIGH
1 PoC
1 Writeup
Analysis
EPSS 0.00
GT Edge AI Platform <v2.0.10 - Info Disclosure
Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.
CWE-284
Dec 22, 2025
CVE-2025-63662
7.5
HIGH
1 PoC
1 Writeup
Analysis
EPSS 0.00
GT Edge AI Platform <v2.0.10-dev - Info Disclosure
Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information.
CWE-200
Dec 22, 2025