CVE & Exploit Intelligence Database

Updated 52m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
4 results Clear all
CVE-2023-36136 6.5 MEDIUM EPSS 0.00
PHPJabbers Class Scheduling System 1.0 - Info Disclosure
PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.
CWE-312 Aug 08, 2023
CVE-2023-36137 6.1 MEDIUM EPSS 0.00
PHPJabbers Class Scheduling System 1.0 - XSS
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.
CWE-79 Aug 04, 2023
CVE-2023-36135 7.5 HIGH EPSS 0.00
PHPJabbers Class Scheduling System v1.0 - Info Disclosure
User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Aug 04, 2023
CVE-2023-36134 9.8 CRITICAL EPSS 0.00
PHP Jabbers Class Scheduling System 1.0 - RCE
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
CWE-345 Aug 04, 2023