Exploit Intelligence Platform
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
410 results
Clear all
CVE-2023-47129
8.3
HIGH
1 PoC
Analysis
EPSS 0.05
Statamic < 3.4.13 - Unrestricted File Upload
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.
CWE-434
Nov 10, 2023
CVE-2023-5540
4.7
MEDIUM
1 PoC
EPSS 0.02
Moodle < 3.9.24 - Code Injection
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
CWE-94
Nov 09, 2023
CVE-2023-5539
4.7
MEDIUM
1 PoC
EPSS 0.02
Moodle < 3.9.24 - Code Injection
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CWE-94
Nov 09, 2023
CVE-2023-28330
6.5
MEDIUM
1 PoC
EPSS 0.01
Moodle < 3.9.20 - Improper Input Validation
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CWE-20
Mar 23, 2023
CVE-2023-28329
8.8
HIGH
1 PoC
EPSS 0.00
Moodle < 3.9.20 - SQL Injection
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
CWE-89
Mar 23, 2023
CVE-2023-44770
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Tribalsystems Zenario - XSS
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.
CWE-79
Oct 06, 2023
CVE-2023-44769
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.01
Tribalsystems Zenario - XSS
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.
CWE-79
Oct 25, 2023
CVE-2023-44771
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Tribalsystems Zenario - XSS
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.
CWE-79
Oct 06, 2023
CVE-2023-44763
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms - Unrestricted File Upload
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.
CWE-434
Oct 10, 2023
CVE-2023-44764
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms - XSS
A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).
CWE-79
Oct 06, 2023
CVE-2023-44766
4.8
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms - XSS
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.
CWE-79
Oct 06, 2023
CVE-2023-44762
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms - XSS
A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.
CWE-79
Oct 06, 2023
CVE-2023-44761
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms < 9.2.2 - XSS
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.
CWE-79
Oct 06, 2023
CVE-2023-44765
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms < 9.2.2 - XSS
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
CWE-79
Oct 06, 2023
CVE-2023-44760
4.8
MEDIUM
1 PoC
Analysis
EPSS 0.00
Concretecms Concrete Cms - XSS
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.
CWE-79
Oct 23, 2023
CVE-2023-43341
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
Evolution Evo <3.2.3 - XSS
Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter.
CWE-79
Oct 19, 2023
CVE-2023-43340
5.2
MEDIUM
1 PoC
Analysis
EPSS 0.01
Evolution <3.2.3 - XSS
Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters
CWE-79
Oct 19, 2023
CVE-2023-43876
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
October <3.4.16 - XSS
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.
CWE-79
Sep 28, 2023
CVE-2023-43875
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.03
Subrion CMS <4.2.1 - XSS
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
CWE-79
Oct 19, 2023
CVE-2023-39062
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.35
Spipu HTML2PDF <5.2.8 - XSS
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
CWE-79
Aug 28, 2023