Exploit Intelligence Platform
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
410 results
Clear all
CVE-2020-5504
8.8
HIGH
2 PoCs
Analysis
EPSS 0.22
phpMyAdmin <4.9.4-5.0.1 - SQL Injection
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
CWE-89
Jan 09, 2020
CVE-2020-24913
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.42
Qcubed < 3.1.1 - SQL Injection
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
CWE-89
Mar 04, 2021
CVE-2020-13405
7.5
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.52
Microweber <1.1.20 - Info Disclosure
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CWE-306
Jul 16, 2020
CVE-2020-25540
7.5
HIGH
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.94
Thinkadmin - Path Traversal
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.
CWE-22
Sep 14, 2020
CVE-2020-28948
7.8
HIGH
3 PoCs
Analysis
EPSS 0.77
PHP Archive Tar < 1.4.11 - Insecure Deserialization
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CWE-502
Nov 19, 2020
CVE-2020-18326
8.8
HIGH
1 PoC
Analysis
EPSS 0.02
Subrion CMS <4.2.1 - CSRF
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
CWE-352
Mar 04, 2022
CVE-2020-18325
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.02
Subrion CMS v4.2.1 - XSS
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
CWE-79
Mar 04, 2022
CVE-2020-18324
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.07
Subrion CMS 4.2.1 - XSS
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
CWE-79
Mar 04, 2022
CVE-2020-10963
7.2
HIGH
2 PoCs
Analysis
EPSS 0.22
FrozenNode Laravel-Administrator <5.0.12 - RCE
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.
CWE-434
Mar 25, 2020
CVE-2020-23489
8.8
HIGH
1 PoC
Analysis
EPSS 0.05
Avideo <8.9 - Privilege Escalation
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
CWE-862
Nov 16, 2020
CVE-2020-25627
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.05
Moodle < 3.9.2 - XSS
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
CWE-79
Dec 09, 2020
CVE-2020-28337
7.2
HIGH
1 PoC
Analysis
EPSS 0.14
Microweber < 1.1.20 - Path Traversal
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CWE-22
Feb 15, 2021
CVE-2020-14209
8.8
HIGH
1 PoC
Analysis
EPSS 0.10
Dolibarr < 11.0.5 - Unrestricted File Upload
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
CWE-434
Sep 02, 2020
CVE-2020-28413
5.3
MEDIUM
2 PoCs
Analysis
EPSS 0.02
Mantisbt < 2.24.4 - SQL Injection
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
CWE-89
Dec 30, 2020
CVE-2020-29156
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.13
Woocommerce < 4.7.0 - IDOR
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
CWE-639
Dec 27, 2020
CVE-2020-36947
7.1
HIGH
1 PoC
Analysis
EPSS 0.00
LibreNMS 1.46 - Authenticated SQL Injection
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.
CWE-89
Jan 27, 2026
CVE-2020-28838
3.5
LOW
1 PoC
Analysis
EPSS 0.00
Opencart - CSRF
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.
CWE-352
Dec 11, 2020
CVE-2020-29471
4.8
MEDIUM
1 PoC
Analysis
EPSS 0.00
OpenCart 3.0.3.6 - XSS
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.
CWE-79
Dec 29, 2020
CVE-2020-29470
4.8
MEDIUM
1 PoC
Analysis
EPSS 0.00
OpenCart 3.0.3.6 - XSS
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
CWE-79
Dec 29, 2020
CVE-2020-15227
8.7
HIGH
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Nette <2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 - Code Injection
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
CWE-74
Oct 01, 2020