Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
410 results Clear all
CVE-2019-7139 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.60
Magento <2.1.18-2.3.2 - SQL Injection
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CWE-89 Apr 10, 2019
CVE-2019-12616 6.5 MEDIUM 2 PoCs Analysis EPSS 0.55
Phpmyadmin < 4.9.0 - CSRF
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
CWE-352 Jun 05, 2019
CVE-2019-6339 9.8 CRITICAL 1 PoC Analysis EPSS 0.76
Drupal < 7.62 - Improper Input Validation
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.
CWE-20 Jan 22, 2019
CVE-2019-19208 9.8 CRITICAL 1 PoC Analysis EPSS 0.39
Codiad Web IDE <2.8.4 - Code Injection
Codiad Web IDE through 2.8.4 allows PHP Code injection.
CWE-94 Mar 16, 2020
CVE-2019-3810 6.1 MEDIUM 2 PoCs Analysis EPSS 0.08
Moodle < 3.1.15 - XSS
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
CWE-79 Mar 25, 2019
CVE-2019-16405 7.2 HIGH 2 PoCs Analysis EPSS 0.09
Centreon Web , 18.10.x , 19.04.x , 19.10.x <2.8.30 <18.10.8 <19.04.5 - Remote Code Execution
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.
Nov 21, 2019
CVE-2019-7357 8.8 HIGH 1 PoC Analysis EPSS 0.02
Subrion CMS 4.2.1 - CSRF
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
CWE-352 Nov 10, 2020
CVE-2019-1010054 8.8 HIGH 1 PoC Analysis EPSS 0.01
Dolibarr 7.0.0 - CSRF
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
CWE-352 Jul 18, 2019
CVE-2019-19576 9.8 CRITICAL 2 PoCs Analysis EPSS 0.51
verot.net class.upload <2.0.4 - Info Disclosure
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
CWE-434 Dec 04, 2019
CVE-2019-19634 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
verot.net class.upload <2.0.4 - Info Disclosure
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
CWE-434 Dec 17, 2019
CVE-2019-16197 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Dolibarr 10.0.1 - XSS
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
CWE-79 Sep 16, 2019
CVE-2019-12922 6.5 MEDIUM 1 PoC Analysis EPSS 0.42
Phpmyadmin < 4.9.0.1 - CSRF
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CWE-352 Sep 13, 2019
CVE-2019-16173 5.4 MEDIUM 1 PoC Analysis EPSS 0.01
LimeSurvey <3.17.14 - XSS
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
CWE-79 Sep 09, 2019
CVE-2019-14470 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.28
cosenary Instagram-PHP-API <4.9.32 - XSS
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
CWE-79 Sep 04, 2019
CVE-2019-25317 6.4 MEDIUM 1 PoC Analysis EPSS 0.00
Kimai 2 - XSS
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.
CWE-79 Feb 11, 2026
CVE-2019-14537 9.8 CRITICAL 1 PoC Analysis EPSS 0.15
YOURLS <1.7.3 - Auth Bypass
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
CWE-843 Aug 07, 2019
CVE-2019-3847 4.8 MEDIUM 1 PoC Analysis EPSS 0.01
Moodle < 3.1.17 - XSS
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
CWE-79 Mar 27, 2019
CVE-2019-10874 8.8 HIGH 1 PoC Analysis EPSS 0.00
Bolt < 3.6.7 - CSRF
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
CWE-352 Apr 05, 2019
CVE-2019-9553 6.1 MEDIUM 1 PoC Analysis EPSS 0.01
Bolt 3.6.4 - XSS
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
CWE-79 Dec 31, 2019
CVE-2019-25710 8.2 HIGH 1 PoC Analysis EPSS 0.00
Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
CWE-89 Apr 12, 2026