Latest Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,640 results
Clear all
CVE-2025-32140
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
CWE-434
Apr 10, 2025
CVE-2025-32641
9.6
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Anant Addons for Elementor <1.1.5 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.
CWE-352
Apr 09, 2025
CVE-2025-31033
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Buddypress Humanity <1.2 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.
CWE-352
Apr 09, 2025
CVE-2025-2807
8.8
HIGH
2 PoCs
Analysis
EPSS 0.01
Stylemixthemes Motors - Car Dealer, C... - Missing Authorization
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.
CWE-862
Apr 08, 2025
CVE-2025-32118
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.00
NiteoThemes CMP - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
CWE-434
Apr 04, 2025
CVE-2025-30911
9.9
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.
CWE-94
Apr 01, 2025
CVE-2025-2249
8.8
HIGH
2 PoCs
Analysis
EPSS 0.02
SoJ SoundSlides <1.2.2 - RCE
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-434
Mar 29, 2025
CVE-2025-30772
8.8
HIGH
2 PoCs
Analysis
EPSS 0.00
WPClever WPC Smart Upsell Funnel for WooCommerce <3.0.4 - Missing Authorization
Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through <= 3.0.4.
CWE-862
Mar 27, 2025
CVE-2025-28915
9.1
CRITICAL
3 PoCs
Analysis
EPSS 0.25
ThemeEgg ToolKit <1.2.9 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.
CWE-434
Mar 11, 2025
CVE-2025-1307
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.28
Spicethemes Newscrunch < 1.8.4.1 - Missing Authorization
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CWE-862
Mar 04, 2025
CVE-2025-1306
8.8
HIGH
2 PoCs
Analysis
EPSS 0.02
Spicethemes Newscrunch < 1.8.4.1 - CSRF
The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352
Mar 04, 2025
CVE-2025-1639
8.8
HIGH
2 PoCs
Analysis
EPSS 0.11
Crowdytheme Arolax < 1.7 - Missing Authorization
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.
CWE-862
Mar 04, 2025
CVE-2025-25101
9.6
CRITICAL
2 PoCs
Analysis
EPSS 0.01
MetricThemes Munk Sites <1.0.8 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.
CWE-352
Feb 07, 2025
CVE-2025-23942
9.1
CRITICAL
2 PoCs
Analysis
EPSS 0.45
NgocCode WP Load Gallery <2.1.6 - RCE
Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Upload a Web Shell to a Web Server.This issue affects WP Load Gallery: from n/a through <= 2.1.6.
CWE-434
Jan 22, 2025
CVE-2025-23922
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.03
Harsh iSpring Embedder - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a Web Server.This issue affects iSpring Embedder: from n/a through <= 1.0.
CWE-352
Jan 16, 2025
CVE-2025-1489
6.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Tchgdns Wp-appbox < 4.5.5 - XSS
The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CWE-79
Feb 21, 2025
CVE-2025-12097
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
NI System Web Server <2012 - Info Disclosure
There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. This vulnerability existed in the NI System Web Server 2012 and prior versions. It was fixed in 2013.
CWE-23
Dec 04, 2025
CVE-2025-62222
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Microsoft Github Copilot Chat < 0.32.5 - Command Injection
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.
CWE-20
Nov 11, 2025
CVE-2025-13401
6.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Autoptimize <3.1.13 - XSS
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CWE-79
Dec 03, 2025
CVE-2025-55816
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
HotelDruid <3.0.7 - XSS
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
CWE-79
Dec 11, 2025