CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
19 results Clear all
CVE-2025-7461 7.3 HIGH 1 PoC Analysis EPSS 0.00
Modern Bag 1.0 - SQL Injection
A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument proId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Jul 12, 2025
CVE-2025-46173 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Code-projects Online Exam Mastering System - XSS
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.
CWE-79 May 27, 2025
CVE-2025-3969 6.3 MEDIUM 1 PoC Analysis EPSS 0.00
Codeprojects News Publishing Site Dashboard 1.0 - Unrestricted Upload
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-284 Apr 27, 2025
CVE-2025-28121 6.1 MEDIUM 2 PoCs Analysis EPSS 0.01
Code-projects Online Exam Mastering System - XSS
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.
CWE-79 Apr 21, 2025
CVE-2025-3243 6.3 MEDIUM 3 PoCs Analysis EPSS 0.00
code-projects Patient Record Management System 1.0 - SQL Injection
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dental_form.php. The manipulation of the argument itr_no/dental_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Apr 04, 2025
CVE-2024-57487 6.5 MEDIUM 2 PoCs Analysis EPSS 0.45
Car Rental System 1.0 File Upload RCE (Authenticated)
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.
CWE-94 Jan 13, 2025
CVE-2024-10758 7.3 HIGH 1 PoC Analysis EPSS 0.00
Anirbandutta9 News-buzz - SQL Injection
A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
CWE-89 Nov 04, 2024
CVE-2024-10140 6.3 MEDIUM 1 PoC Analysis EPSS 0.14
Pharmacy Management System 1.0 - SQL Injection
A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. Affected by this issue is some unknown functionality of the file /manage_supplier.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-89 Oct 19, 2024
CVE-2024-8868 7.3 HIGH 1 PoC EPSS 0.00
Code-projects Crud Operation System - SQL Injection
A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file savedata.php. The manipulation of the argument sname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-89 Sep 15, 2024
CVE-2023-46022 7.8 HIGH 2 PoCs Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - SQL Injection
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.
CWE-89 Nov 14, 2023
CVE-2023-46021 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - SQL Injection
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
CWE-89 Nov 13, 2023
CVE-2023-46020 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - XSS
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
CWE-79 Nov 13, 2023
CVE-2023-46019 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - XSS
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.
CWE-79 Nov 13, 2023
CVE-2023-46018 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - SQL Injection
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
CWE-89 Nov 13, 2023
CVE-2023-46017 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - SQL Injection
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
CWE-89 Nov 13, 2023
CVE-2023-46016 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - XSS
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.
CWE-79 Nov 13, 2023
CVE-2023-46015 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - XSS
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.
CWE-79 Nov 13, 2023
CVE-2023-46014 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Code-Projects Blood Bank 1.0 - SQL Injection
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
CWE-89 Nov 13, 2023
CVE-2023-1415 6.3 MEDIUM 1 PoC Analysis EPSS 0.00
Simple Art Gallery 1.0 - Unrestricted Upload
A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the file adminHome.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-223126 is the identifier assigned to this vulnerability.
CWE-434 Mar 15, 2023