Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
410 results Clear all
CVE-2020-5504 8.8 HIGH 2 PoCs Analysis EPSS 0.22
phpMyAdmin <4.9.4-5.0.1 - SQL Injection
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
CWE-89 Jan 09, 2020
CVE-2020-24913 9.8 CRITICAL 2 PoCs Analysis EPSS 0.42
Qcubed < 3.1.1 - SQL Injection
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
CWE-89 Mar 04, 2021
CVE-2020-13405 7.5 HIGH 2 PoCs Analysis NUCLEI EPSS 0.52
Microweber <1.1.20 - Info Disclosure
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CWE-306 Jul 16, 2020
CVE-2020-25540 7.5 HIGH EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.94
Thinkadmin - Path Traversal
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.
CWE-22 Sep 14, 2020
CVE-2020-28948 7.8 HIGH 3 PoCs Analysis EPSS 0.77
PHP Archive Tar < 1.4.11 - Insecure Deserialization
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CWE-502 Nov 19, 2020
CVE-2020-18326 8.8 HIGH 1 PoC Analysis EPSS 0.02
Subrion CMS <4.2.1 - CSRF
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
CWE-352 Mar 04, 2022
CVE-2020-18325 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Subrion CMS v4.2.1 - XSS
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
CWE-79 Mar 04, 2022
CVE-2020-18324 6.1 MEDIUM 1 PoC Analysis EPSS 0.07
Subrion CMS 4.2.1 - XSS
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
CWE-79 Mar 04, 2022
CVE-2020-10963 7.2 HIGH 2 PoCs Analysis EPSS 0.22
FrozenNode Laravel-Administrator <5.0.12 - RCE
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.
CWE-434 Mar 25, 2020
CVE-2020-23489 8.8 HIGH 1 PoC Analysis EPSS 0.05
Avideo <8.9 - Privilege Escalation
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
CWE-862 Nov 16, 2020
CVE-2020-25627 6.1 MEDIUM 1 PoC Analysis EPSS 0.05
Moodle < 3.9.2 - XSS
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
CWE-79 Dec 09, 2020
CVE-2020-28337 7.2 HIGH 1 PoC Analysis EPSS 0.14
Microweber < 1.1.20 - Path Traversal
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CWE-22 Feb 15, 2021
CVE-2020-14209 8.8 HIGH 1 PoC Analysis EPSS 0.10
Dolibarr < 11.0.5 - Unrestricted File Upload
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
CWE-434 Sep 02, 2020
CVE-2020-28413 5.3 MEDIUM 2 PoCs Analysis EPSS 0.02
Mantisbt < 2.24.4 - SQL Injection
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
CWE-89 Dec 30, 2020
CVE-2020-29156 5.3 MEDIUM 1 PoC Analysis EPSS 0.13
Woocommerce < 4.7.0 - IDOR
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
CWE-639 Dec 27, 2020
CVE-2020-36947 7.1 HIGH 1 PoC Analysis EPSS 0.00
LibreNMS 1.46 - Authenticated SQL Injection
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.
CWE-89 Jan 27, 2026
CVE-2020-28838 3.5 LOW 1 PoC Analysis EPSS 0.00
Opencart - CSRF
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.
CWE-352 Dec 11, 2020
CVE-2020-29471 4.8 MEDIUM 1 PoC Analysis EPSS 0.00
OpenCart 3.0.3.6 - XSS
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.
CWE-79 Dec 29, 2020
CVE-2020-29470 4.8 MEDIUM 1 PoC Analysis EPSS 0.00
OpenCart 3.0.3.6 - XSS
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
CWE-79 Dec 29, 2020
CVE-2020-15227 8.7 HIGH EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.94
Nette <2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 - Code Injection
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
CWE-74 Oct 01, 2020