Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
410 results Clear all
CVE-2024-37843 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.89
Craftcms Craft Cms < 3.7.31 - SQL Injection
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CWE-89 Jun 25, 2024
CVE-2024-2653 8.2 HIGH 1 PoC Analysis EPSS 0.05
amphttp <unknown> - Buffer Overflow
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
Apr 03, 2024
CVE-2024-58303 HIGH 1 PoC Analysis EPSS 0.00
FoF Pretty Mail 1.1.2 - Code Injection
FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.
CWE-1336 Dec 11, 2025
CVE-2024-22640 7.5 HIGH 1 PoC Analysis EPSS 0.01
TCPDF <=6.6.5 - DoS
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
CWE-1333 Apr 19, 2024
CVE-2024-29686 7.2 HIGH 1 PoC Analysis EPSS 0.04
Winter CMS v.1.2.3 - SSTI
Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.
CWE-97 Mar 29, 2024
CVE-2023-1313 8.8 HIGH 1 PoC 1 Writeup Analysis EPSS 0.01
Agentejo Cockpit < 2.4.0 - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
CWE-434 Mar 10, 2023
CVE-2023-33568 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.90
Dolibarr <16.0.5 - Info Disclosure
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
CWE-552 Jun 13, 2023
CVE-2023-41892 10.0 CRITICAL EXPLOITED 7 PoCs Analysis NUCLEI EPSS 0.94
Craft CMS unauthenticated Remote Code Execution (RCE)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CWE-94 Sep 13, 2023
CVE-2023-0315 8.8 HIGH 3 PoCs Analysis EPSS 0.89
froxlor/froxlor <2.0.8 - Command Injection
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
CWE-77 Jan 16, 2023
CVE-2023-47125 4.7 MEDIUM 1 PoC Analysis EPSS 0.00
Typo3 Html Sanitizer < 1.5.3 - XSS
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CWE-79 Nov 14, 2023
CVE-2023-29689 9.8 CRITICAL 2 PoCs Analysis EPSS 0.49
Pyrocms - Remote Code Execution
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
Aug 04, 2023
CVE-2023-30253 8.8 HIGH 8 PoCs Analysis EPSS 0.89
Dolibarr Erp/crm < 17.0.1 - OS Command Injection
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
CWE-78 May 29, 2023
CVE-2023-24249 7.2 HIGH 2 PoCs Analysis EPSS 0.48
Laravel-Admin <1.8.19 - RCE
An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
CWE-434 Feb 27, 2023
CVE-2023-1545 7.5 HIGH 5 PoCs Analysis EPSS 0.15
nilsteampassnet/teampass <3.0.0.23 - SQL Injection
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
CWE-89 Mar 21, 2023
CVE-2023-38873 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
gugoan Economizzer <0.9-beta1 - CSRF
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.
CWE-1021 Sep 28, 2023
CVE-2023-41564 6.1 MEDIUM 1 PoC Analysis EPSS 0.20
Cockpit CMS <2.6.3 - RCE
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
CWE-434 Sep 08, 2023
CVE-2023-6654 6.3 MEDIUM 1 PoC Analysis EPSS 0.02
PHPEMS 6.x/7.x/8.x/9.0 - Deserialization
A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247357 was assigned to this vulnerability.
CWE-502 Dec 10, 2023
CVE-2023-4197 7.5 HIGH 1 PoC Analysis EPSS 0.51
Dolibarr Erp/crm < 18.0.1 - Injection
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
CWE-74 Nov 01, 2023
CVE-2023-30943 6.5 MEDIUM 3 PoCs Analysis NUCLEI EPSS 0.17
Moodle - Path Traversal
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
CWE-610 May 02, 2023
CVE-2023-49052 8.8 HIGH 1 PoC Analysis EPSS 0.26
Microweber <2.0.4 - RCE
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.
CWE-434 Nov 30, 2023