Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
410 results Clear all
CVE-2018-7251 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.91
Anchor < 0.12.7 - Information Disclosure
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
CWE-200 Feb 19, 2018
CVE-2018-16854 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
Moodle <3.6 - CSRF
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.
CWE-352 Nov 26, 2018
CVE-2018-11564 4.8 MEDIUM 2 PoCs Analysis EPSS 0.01
Pagekit < 1.0.13 - XSS
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
CWE-79 Jun 02, 2018
CVE-2018-25157 6.4 MEDIUM 1 PoC Analysis EPSS 0.00
Phraseanet 4.0.3 - XSS
Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.
CWE-79 Feb 11, 2026
CVE-2018-17057 9.8 CRITICAL 1 PoC Analysis EPSS 0.52
TCPDF <6.2.22 - Deserialization
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
CWE-502 Sep 14, 2018
CVE-2018-1000888 8.8 HIGH 1 PoC Analysis EPSS 0.29
PEAR Archive_Tar <1.4.3 - Code Injection
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.
CWE-502 Dec 28, 2018
CVE-2018-20418 4.8 MEDIUM 1 PoC Analysis EPSS 0.00
Craftcms Craft Cms - XSS
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
CWE-79 Dec 24, 2018
CVE-2018-19933 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Bolt CMS <3.6.2 - XSS
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
CWE-79 Dec 17, 2018
CVE-2018-19799 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Dolibarr ERP/CRM <8.0.3 - XSS
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
CWE-79 Dec 26, 2018
CVE-2018-19277 8.8 HIGH 1 PoC Analysis EPSS 0.03
PHPOffice PhpSpreadsheet <1.5.0 - XSS
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
CWE-91 Nov 14, 2018
CVE-2018-19458 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.80
PHP Proxy 3.0.3 - Info Disclosure
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.
CWE-287 Nov 22, 2018
CVE-2018-15845 8.8 HIGH 1 PoC Analysis EPSS 0.01
Gleezcms Gleez Cms - CSRF
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
CWE-352 Aug 25, 2018
CVE-2018-14059 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Pimcore - XSS
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
CWE-79 Aug 24, 2018
CVE-2018-14057 8.8 HIGH 1 PoC Analysis EPSS 0.00
Pimcore <5.3.0 - CSRF
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
CWE-352 Aug 17, 2018
CVE-2018-14840 6.1 MEDIUM 1 PoC Analysis EPSS 0.03
Subrion CMS 4.2.1 - XSS
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
CWE-79 Aug 02, 2018
CVE-2018-14519 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Kirby 2.5.12 - CSRF
An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.
CWE-352 Aug 24, 2022
CVE-2018-14520 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Kirby 2.5.12 - CSRF
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
CWE-79 Aug 24, 2022
CVE-2018-10366 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
October CMS Users <1.4.5 - XSS
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.
CWE-79 Apr 25, 2018
CVE-2018-10188 8.8 HIGH 1 PoC Analysis EPSS 0.01
phpMyAdmin <4.8.0-1 - CSRF
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.
CWE-352 Apr 19, 2018
CVE-2018-7198 6.1 MEDIUM 1 PoC Analysis EPSS 0.01
October < 1.0.431 - XSS
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
CWE-79 Feb 18, 2018