CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
17 results Clear all
CVE-2025-60306 9.9 CRITICAL 1 Writeup EPSS 0.00
code-projects Simple Car Rental System 1.0 - Auth Bypass
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.
CWE-284 Oct 10, 2025
CVE-2025-40731 9.8 CRITICAL EPSS 0.00
Code-projects Daily Expense Manager - SQL Injection
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.
CWE-89 Jun 30, 2025
CVE-2024-34955 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Budget Management - SQL Injection
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
CWE-89 May 15, 2024
CVE-2023-41505 9.8 CRITICAL 1 Writeup EPSS 0.00
Student Enrollment In PHP v1.0 - RCE
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CWE-434 Mar 13, 2024
CVE-2024-24101 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Scholars Tracking System - SQL Injection
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
CWE-89 Mar 12, 2024
CVE-2024-24093 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Scholars Tracking System - SQL Injection
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.
CWE-89 Mar 12, 2024
CVE-2023-41503 9.8 CRITICAL 1 Writeup EPSS 0.00
Student Enrollment In PHP v1.0 - SQL Injection
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
CWE-94 Mar 07, 2024
CVE-2023-41014 9.8 CRITICAL 1 Writeup EPSS 0.00
code-projects.org Online Job Portal 1.0 - SQL Injection
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."
CWE-89 Mar 07, 2024
CVE-2024-24095 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Simple Stock System - SQL Injection
Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
CWE-89 Feb 27, 2024
CVE-2023-41506 9.8 CRITICAL 1 Writeup EPSS 0.00
Student Enrollment In PHP v1.0 - RCE
An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CWE-434 Feb 27, 2024
CVE-2024-25223 9.8 CRITICAL 1 Writeup EPSS 0.00
Simple Admin Panel App v1.0 - SQL Injection
Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.
CWE-89 Feb 14, 2024
CVE-2024-25222 9.8 CRITICAL 1 Writeup EPSS 0.00
Task Manager App v1.0 - SQL Injection
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.
CWE-89 Feb 14, 2024
CVE-2024-25220 9.8 CRITICAL 1 Writeup EPSS 0.00
Task Manager App v1.0 - SQL Injection
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.
CWE-89 Feb 14, 2024
CVE-2024-25307 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Cinema Seat Reservation System 1.0 - SQL Injection
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
CWE-89 Feb 09, 2024
CVE-2023-48078 9.8 CRITICAL 1 Writeup EPSS 0.00
Code-projects Simple Crud Functionality - SQL Injection
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.
CWE-89 Nov 17, 2023
CVE-2023-37627 9.8 CRITICAL EPSS 0.00
Code-projects Online Restaurant Management System - SQL Injection
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.
CWE-89 Jul 12, 2023
CVE-2021-44092 9.8 CRITICAL EPSS 0.00
Code-projects Pharmacy Management - SQL Injection
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
CWE-89 Jan 20, 2022