Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
410 results Clear all
CVE-2022-48150 6.1 MEDIUM 2 PoCs Analysis EPSS 0.00
Shopware - XSS
Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
CWE-79 Apr 21, 2023
CVE-2022-28508 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.01
MantisBT <2.25.2 - XSS
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
CWE-79 May 04, 2022
CVE-2022-26265 9.8 CRITICAL 3 PoCs Analysis EPSS 0.72
Contao Managed Edition <1.5.0 - RCE
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
CWE-78 Mar 18, 2022
CVE-2022-23808 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.49
phpMyAdmin <5.1.2 - Code Injection
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CWE-79 Jan 22, 2022
CVE-2022-39986 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.93
Raspap < 2.8.7 - Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
CWE-77 Aug 01, 2023
CVE-2022-24637 9.8 CRITICAL 9 PoCs Analysis NUCLEI EPSS 0.94
Open Web Analytics <1.7.4 - Info Disclosure
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
CWE-269 Mar 18, 2022
CVE-2022-44136 9.8 CRITICAL 2 PoCs Analysis EPSS 0.01
Zenario CMS <9.3.57186 - RCE
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
Nov 30, 2022
CVE-2022-3766 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.14
Phpmyfaq < 3.1.8 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CWE-79 Oct 31, 2022
CVE-2022-0088 7.4 HIGH 1 PoC Analysis EPSS 0.01
Yourls < 1.8.3 - CSRF
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
CWE-352 Apr 03, 2022
CVE-2022-24894 5.9 MEDIUM 1 PoC Analysis EPSS 0.00
Sensiolabs Symfony < 4.4.50 - Improper Authorization
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4.
CWE-285 Feb 03, 2023
CVE-2022-42092 7.2 HIGH 1 PoC Analysis EPSS 0.02
Backdropcms Backdrop Cms - Unrestricted File Upload
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
CWE-434 Oct 07, 2022
CVE-2022-4407 6.1 MEDIUM 1 PoC Analysis EPSS 0.06
Phpmyfaq < 3.1.9 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CWE-79 Dec 11, 2022
CVE-2022-23409 4.9 MEDIUM 1 PoC Analysis EPSS 0.04
Ethercreative Logs < 3.0.4 - Path Traversal
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
CWE-22 Jan 31, 2022
CVE-2022-24086 9.8 CRITICAL KEV 10 PoCs Analysis NUCLEI EPSS 0.94
Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CWE-20 Feb 16, 2022
CVE-2022-28368 9.8 CRITICAL 5 PoCs Analysis EPSS 0.70
Dompdf 1.2.1 - RCE
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
CWE-79 Apr 03, 2022
CVE-2022-0482 9.1 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.91
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CWE-359 Mar 09, 2022
CVE-2022-0937 5.4 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
Showdoc < 2.10.3 - XSS
Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CWE-79 Mar 14, 2022
CVE-2022-23614 8.8 HIGH 2 PoCs Analysis EPSS 0.28
Symfony Twig < 2.14.11 - Injection
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.
CWE-74 Feb 04, 2022
CVE-2022-35698 10.0 CRITICAL 1 PoC Analysis EPSS 0.03
Adobe Commerce <2.4.4-p1, <2.4.5 - XSS
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
CWE-79 Oct 14, 2022
CVE-2022-26986 7.2 HIGH 1 PoC Analysis EPSS 0.01
ImpressCMS <1.4.3 - SQL Injection
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
CWE-89 Apr 05, 2022