Exploit Intelligence Platform
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
410 results
Clear all
CVE-2020-4040
8.6
HIGH
1 PoC
Analysis
EPSS 0.01
Bolt < 3.7.1 - CSRF
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
CWE-352
Jun 08, 2020
CVE-2020-5295
4.8
MEDIUM
1 PoC
Analysis
EPSS 0.10
OctoberCMS <1.0.466 - Info Disclosure
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).
CWE-829
Jun 03, 2020
CVE-2020-15148
8.9
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.93
Yii 2 <2.0.38 - RCE
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.
CWE-502
Sep 15, 2020
CVE-2020-15873
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.08
Librenms < 1.65.1 - SQL Injection
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
CWE-89
Jul 21, 2020
CVE-2020-13094
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.02
Dolibarr <11.0.4 - XSS
Dolibarr before 11.0.4 allows XSS.
CWE-79
May 18, 2020
CVE-2020-10596
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.01
OpenCart 3.0.3.2 - XSS
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.
CWE-79
Mar 17, 2020
CVE-2020-13693
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.41
bbPress <2.6.5 - Privilege Escalation
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
May 29, 2020
CVE-2020-13157
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
NukeViet 4.4 - CSRF
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.
CWE-352
Jun 23, 2020
CVE-2020-13156
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
NukeViet 4.4 - CSRF
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
CWE-352
Jun 23, 2020
CVE-2020-13155
8.8
HIGH
1 PoC
Analysis
EPSS 0.00
NukeViet 4.4 - CSRF
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
CWE-352
Jun 23, 2020
CVE-2020-8819
8.1
HIGH
1 PoC
Analysis
EPSS 0.00
CardGate Payments <3.1.15 - Auth Bypass
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.
CWE-346
Feb 25, 2020
CVE-2019-12799
8.8
HIGH
1 PoC
Analysis
EPSS 0.24
Shopware < 5.6.0 - Insecure Deserialization
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
CWE-502
Jun 13, 2019
CVE-2019-9194
9.8
CRITICAL
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.93
Std42 Elfinder < 2.1.48 - OS Command Injection
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
CWE-78
Feb 26, 2019
CVE-2019-16172
5.4
MEDIUM
2 PoCs
Analysis
EPSS 0.01
LimeSurvey <3.17.14 - XSS
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
CWE-79
Sep 09, 2019
CVE-2019-11358
6.1
MEDIUM
EXPLOITED
7 PoCs
Analysis
EPSS 0.02
jQuery <3.4.0 - Info Disclosure
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
CWE-1321
Apr 20, 2019
CVE-2019-6340
8.1
HIGH
KEV
16 PoCs
Analysis
NUCLEI
EPSS 0.94
Drupal < 8.5.11 - Insecure Deserialization
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
CWE-502
Feb 21, 2019
CVE-2019-10867
8.8
HIGH
2 PoCs
Analysis
EPSS 0.53
Pimcore < 5.7.1 - Insecure Deserialization
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.
CWE-502
Apr 04, 2019
CVE-2019-15715
7.2
HIGH
2 PoCs
Analysis
EPSS 0.21
Mantisbt < 1.3.20 - OS Command Injection
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
CWE-78
Oct 09, 2019
CVE-2019-8331
6.1
MEDIUM
3 PoCs
Analysis
EPSS 0.02
Bootstrap < 3.4.1 - XSS
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
CWE-79
Feb 20, 2019
CVE-2019-10909
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Sensiolabs Symfony < 2.7.51 - XSS
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
CWE-79
May 16, 2019