Latest Vulnerabilities with Public Exploits

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
53,639 results Clear all
CVE-2025-15474 MEDIUM 1 PoC Analysis EPSS 0.00
AuntyFey Smart Combination Lock - DoS
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.
CWE-770 Jan 07, 2026
CVE-2025-10493 5.3 MEDIUM 1 PoC Analysis EPSS 0.03
Chained Quiz <1.3.4 - Insecure Direct Object Reference
The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by manipulating the chained_completion_id cookie value, allowing them to alter quiz answers, scores, and results of any user. The vulnerability was partially patched in versions 1.3.4 and 1.3.5.
CWE-639 Sep 18, 2025
CVE-2025-68461 7.2 HIGH KEV 2 PoCs Analysis EPSS 0.09
Roundcube Webmail < 1.5.12 - XSS
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
CWE-79 Dec 18, 2025
CVE-2025-66209 9.9 CRITICAL 1 PoC Analysis EPSS 0.00
Coolify <4.0.0-beta.451 - Command Injection
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.
CWE-78 Dec 23, 2025
CVE-2025-65270 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Clincapture Captivate Electronic Data Capture - XSS
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
CWE-79 Dec 22, 2025
CVE-2025-45146 9.8 CRITICAL 1 PoC 2 Writeups Analysis EPSS 0.00
Codefuse Modelcache < 0.2.0 - Insecure Deserialization
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.
CWE-502 Aug 11, 2025
CVE-2025-13156 8.8 HIGH 1 PoC Analysis EPSS 0.00
Vitepos - Point of Sale (POS) for WooCommerce plugin <= 3.3.0 - Arbitrary File Upload
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the save_update_category_img() function accepting user-supplied file types without validation when processing category images. This makes it possible for authenticated attackers, with subscriber level access and above, to upload arbitrary files on the affected site's server which makes remote code execution possible.
CWE-434 Nov 21, 2025
CVE-2025-13339 7.5 HIGH 1 PoC Analysis EPSS 0.00
Hippoo Mobile App <1.7.1 - Path Traversal
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CWE-22 Dec 10, 2025
CVE-2025-13159 7.1 HIGH 1 PoC Analysis EPSS 0.00
Flo Forms <1.0.43 - XSS
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.0.43. This is due to the plugin allowing SVG file uploads via an unauthenticated AJAX endpoint (`flo_form_submit`) without proper file content validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when an administrator views the uploaded file in the WordPress admin interface, leading to potential full site compromise.
CWE-79 Nov 21, 2025
CVE-2025-12904 7.2 HIGH 1 PoC Analysis EPSS 0.00
H5PxAPIkatchu <0.4.17 - XSS
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CWE-79 Nov 14, 2025
CVE-2025-10142 4.9 MEDIUM 1 PoC Analysis EPSS 0.00
PagBank/PagSeguro Connect para WooCommerce <4.44.3 - SQL Injection
The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 4.44.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89 Sep 10, 2025
CVE-2025-10175 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
WP Links Page <4.9.6 - SQL Injection
The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89 Oct 11, 2025
CVE-2025-8091 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
EventON Lite <2.4.6 - Info Disclosure
The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
CWE-200 Aug 15, 2025
CVE-2025-9886 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Trinity Audio - Text to Speech AI <5.20.2 - CSRF
The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.20.2. This is due to missing or incorrect nonce validation in the '/admin/inc/post-management.php' file. This makes it possible for unauthenticated attackers to activate/deactivate posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Oct 04, 2025
CVE-2025-12139 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.16
Google Drive WordPress Plugin <1.5.3 - Info Disclosure
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.
CWE-200 Nov 05, 2025
CVE-2025-65857 7.5 HIGH 1 PoC Analysis EPSS 0.00
Xiongmai XM530 IP cameras - Info Disclosure
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
CWE-359 Dec 22, 2025
CVE-2025-67586 4.7 MEDIUM 1 PoC Analysis EPSS 0.01
Highlight and Share <5.2.0 - RCE
Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0.
CWE-862 Dec 09, 2025
CVE-2025-63664 7.5 HIGH 1 PoC 1 Writeup Analysis EPSS 0.00
GT Edge AI Platform <2.0.10-dev - Info Disclosure
Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.
CWE-284 Dec 22, 2025
CVE-2025-63663 7.5 HIGH 1 PoC 1 Writeup Analysis EPSS 0.00
GT Edge AI Platform <v2.0.10 - Info Disclosure
Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.
CWE-284 Dec 22, 2025
CVE-2025-63662 7.5 HIGH 1 PoC 1 Writeup Analysis EPSS 0.00
GT Edge AI Platform <v2.0.10-dev - Info Disclosure
Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information.
CWE-200 Dec 22, 2025