CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
18,080 results Clear all
CVE-2003-1533 1 PoC Analysis EPSS 0.00
Phppass - SQL Injection
SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.
CWE-89 Dec 31, 2003
CVE-2003-1532 1 PoC Analysis EPSS 0.00
Julien Desaunay Phpmyshop - SQL Injection
SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.
CWE-89 Dec 31, 2003
CVE-2003-1530 1 PoC Analysis EPSS 0.01
Phpbb - SQL Injection
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.
CWE-89 Dec 31, 2003
CVE-2003-1244 1 PoC Analysis EPSS 0.02
Phpbb - SQL Injection
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.
CWE-89 Dec 31, 2003
CVE-2003-1523 EPSS 0.00
Dbmail - SQL Injection
SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.
CWE-89 Dec 31, 2003
CVE-2003-1458 EPSS 0.00
Ttcms - SQL Injection
SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.
CWE-89 Dec 31, 2003
CVE-2003-1340 EPSS 0.00
Phpnuke Php-nuke - SQL Injection
Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.
CWE-89 Dec 31, 2003
CVE-2003-1504 1 PoC Analysis EPSS 0.00
Goldscripts Goldlink - SQL Injection
SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.
CWE-89 Dec 31, 2003
CVE-2003-1520 1 PoC Analysis EPSS 0.01
Fuzzymonkey Myclassifieds - SQL Injection
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
CWE-89 Dec 31, 2003
CVE-2003-1435 1 PoC Analysis EPSS 0.00
Francisco Burzi Php-nuke - SQL Injection
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
CWE-89 Dec 31, 2003
CVE-2003-0845 1 PoC Analysis EPSS 0.17
JBoss <3.2.1-3.0.8 - RCE
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.
CWE-89 Nov 17, 2003
CVE-2003-0286 EPSS 0.01
Snitz Forums <3.4.03-3.4.07 - SQL Injection
SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.
CWE-89 Jun 16, 2003
CVE-2003-0377 1 PoC Analysis EPSS 0.01
iisPROTECT <2.2-r4 - SQL Injection
SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.
CWE-89 Jun 16, 2003
CVE-2002-2383 EPSS 0.00
F2html.pl - SQL Injection
SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.
CWE-89 Dec 31, 2002
CVE-2002-2305 EPSS 0.00
Phpsecure.org Immobilier - SQL Injection
SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter.
CWE-89 Dec 31, 2002
CVE-2002-2304 1 PoC Analysis EPSS 0.00
Myphpsoft Myphplinks - SQL Injection
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.
CWE-89 Dec 31, 2002
CVE-2002-2252 EPSS 0.00
Atthat.com Thatware < 0.5 - SQL Injection
SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.
CWE-89 Dec 31, 2002
CVE-2002-2277 EPSS 0.00
Portail Web Php - SQL Injection
SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.
CWE-89 Dec 31, 2002
CVE-2002-2391 EPSS 0.00
Webchat - SQL Injection
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
CWE-89 Dec 31, 2002
CVE-2002-0999 EPSS 0.01
Care 2002 - SQL Injection
Multiple SQL injection vulnerabilities in CARE 2002 before beta 1.0.02 allow remote attackers to perform unauthorized database operations.
CWE-89 Oct 04, 2002