Exploit Intelligence Platform
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
410 results
Clear all
CVE-2022-48150
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.00
Shopware - XSS
Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
CWE-79
Apr 21, 2023
CVE-2022-28508
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.01
MantisBT <2.25.2 - XSS
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
CWE-79
May 04, 2022
CVE-2022-26265
9.8
CRITICAL
3 PoCs
Analysis
EPSS 0.72
Contao Managed Edition <1.5.0 - RCE
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
CWE-78
Mar 18, 2022
CVE-2022-23808
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.49
phpMyAdmin <5.1.2 - Code Injection
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CWE-79
Jan 22, 2022
CVE-2022-39986
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.93
Raspap < 2.8.7 - Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
CWE-77
Aug 01, 2023
CVE-2022-24637
9.8
CRITICAL
9 PoCs
Analysis
NUCLEI
EPSS 0.94
Open Web Analytics <1.7.4 - Info Disclosure
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
CWE-269
Mar 18, 2022
CVE-2022-44136
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
Zenario CMS <9.3.57186 - RCE
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
Nov 30, 2022
CVE-2022-3766
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.14
Phpmyfaq < 3.1.8 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CWE-79
Oct 31, 2022
CVE-2022-0088
7.4
HIGH
1 PoC
Analysis
EPSS 0.01
Yourls < 1.8.3 - CSRF
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
CWE-352
Apr 03, 2022
CVE-2022-24894
5.9
MEDIUM
1 PoC
Analysis
EPSS 0.00
Sensiolabs Symfony < 4.4.50 - Improper Authorization
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4.
CWE-285
Feb 03, 2023
CVE-2022-42092
7.2
HIGH
1 PoC
Analysis
EPSS 0.02
Backdropcms Backdrop Cms - Unrestricted File Upload
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
CWE-434
Oct 07, 2022
CVE-2022-4407
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.06
Phpmyfaq < 3.1.9 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CWE-79
Dec 11, 2022
CVE-2022-23409
4.9
MEDIUM
1 PoC
Analysis
EPSS 0.04
Ethercreative Logs < 3.0.4 - Path Traversal
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
CWE-22
Jan 31, 2022
CVE-2022-24086
9.8
CRITICAL
KEV
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CWE-20
Feb 16, 2022
CVE-2022-28368
9.8
CRITICAL
5 PoCs
Analysis
EPSS 0.70
Dompdf 1.2.1 - RCE
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
CWE-79
Apr 03, 2022
CVE-2022-0482
9.1
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.91
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CWE-359
Mar 09, 2022
CVE-2022-0937
5.4
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
Showdoc < 2.10.3 - XSS
Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CWE-79
Mar 14, 2022
CVE-2022-23614
8.8
HIGH
2 PoCs
Analysis
EPSS 0.28
Symfony Twig < 2.14.11 - Injection
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.
CWE-74
Feb 04, 2022
CVE-2022-35698
10.0
CRITICAL
1 PoC
Analysis
EPSS 0.03
Adobe Commerce <2.4.4-p1, <2.4.5 - XSS
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
CWE-79
Oct 14, 2022
CVE-2022-26986
7.2
HIGH
1 PoC
Analysis
EPSS 0.01
ImpressCMS <1.4.3 - SQL Injection
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
CWE-89
Apr 05, 2022