Latest Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,700 results
Clear all
CVE-2025-53694
7.5
HIGH
SSVC PoC
2 PoCs
Analysis
EPSS 0.00
Sitecore XM/X - Info Disclosure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
CWE-200
Sep 03, 2025
CVE-2025-53691
8.8
HIGH
SSVC PoC
2 PoCs
Analysis
EPSS 0.05
Sitecore XM/X - RCE
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
CWE-502
Sep 03, 2025
CVE-2025-53693
9.8
CRITICAL
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Sitecore XM/X <10.5 - Cache Poisoning
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
CWE-470
Sep 03, 2025
CVE-2025-50565
6.5
MEDIUM
2 PoCs
Analysis
EPSS 0.00
Doubo ERP 1.0 - SQL Injection
Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker.
CWE-89
Sep 02, 2025
CVE-2025-9478
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
Google Chrome <139.0.7258.154 - Use After Free
Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE-416
Aug 26, 2025
CVE-2025-8714
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
PostgreSQL <17.6, <16.10, <15.14, <14.19, <13.22 - Code Injection
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
CWE-829
Aug 14, 2025
CVE-2025-2776
9.3
CRITICAL
KEV
SSVC ACTIVE
2 PoCs
Analysis
NUCLEI
EPSS 0.63
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
CWE-611
May 07, 2025
CVE-2025-9728
4.3
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
givanz Vvveb 1.0.7.2 - XSS
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.
CWE-94
Aug 31, 2025
CVE-2025-48799
7.8
HIGH
3 PoCs
Analysis
EPSS 0.02
Windows Update Service - Privilege Escalation
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
CWE-59
Jul 08, 2025
CVE-2025-50383
8.1
HIGH
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Easy!Appointments v1.5.1 - SQL Injection
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
CWE-89
Aug 25, 2025
CVE-2025-0309
MEDIUM
1 PoC
Analysis
EPSS 0.00
Netskope Client - Privilege Escalation
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
CWE-295
Aug 14, 2025
CVE-2025-55579
5.4
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
SolidInvoice <2.3.7 - XSS
SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.
CWE-79
Aug 29, 2025
CVE-2025-51643
2.4
LOW
SSVC PoC
1 PoC
Analysis
EPSS 0.00
Meitrack T366l-g Firmware - Information Disclosure
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter
CWE-200
Aug 28, 2025
CVE-2025-55580
5.4
MEDIUM
SSVC PoC
1 PoC
Analysis
EPSS 0.00
SolidInvoice <2.3.7 - XSS
SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.
CWE-79
Aug 29, 2025
CVE-2025-47987
7.8
HIGH
1 PoC
Analysis
EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.21073 - Integer Overflow
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
CWE-190
Jul 08, 2025
CVE-2025-43960
8.6
HIGH
1 PoC
Analysis
EPSS 0.00
Adminer - Insecure Deserialization
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.
CWE-502
Aug 25, 2025
CVE-2025-27363
8.1
HIGH
KEV
SSVC ACTIVE
3 PoCs
Analysis
EPSS 0.69
FreeType <2.13.0 - Buffer Overflow
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
CWE-787
Mar 11, 2025
CVE-2025-34159
8.8
HIGH
1 PoC
Analysis
EPSS 0.01
Coollabs Coolify < 4.0.0 - Code Injection
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
CWE-94
Aug 27, 2025
CVE-2025-26529
8.3
HIGH
2 PoCs
Analysis
EPSS 0.01
Moodle < 4.1.16 - XSS
Description information displayed in the site administration live log
required additional sanitizing to prevent a stored XSS risk.
CWE-79
Feb 24, 2025
CVE-2025-54939
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
Litespeedtech Litespeed Web Adc < 3.3.1 - Memory Leak
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
CWE-770
Aug 01, 2025