Exploit Intelligence Platform
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
Showing latest vulnerabilities
CVE-2026-4564
1 Writeup
yangzongzhuan RuoYi Quartz Job job code injection
CWE-74
Mar 22, 2026
CVE-2026-4563
MacCMS Member Order Detail User.php order_info authorization
CWE-285
Mar 22, 2026
CVE-2026-2580
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
CWE-89
Mar 22, 2026
CVE-2026-4562
MacCMS Timming API Endpoint Timming.php weak authentication
CWE-287
Mar 22, 2026
CVE-2026-4558
8.8
HIGH
Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection
CWE-77
Mar 22, 2026
CVE-2026-4557
4.3
MEDIUM
code-projects Exam Form Submission update_s1.php cross site scripting
CWE-94
Mar 22, 2026
CVE-2026-4555
8.8
HIGH
1 Writeup
D-Link DIR-513 boa formEasySetTimezone memory corruption
CWE-121
Mar 22, 2026
CVE-2026-4554
6.3
MEDIUM
1 Writeup
Tenda F453 WriteFacMac FormWriteFacMac privilege escalation
CWE-74
Mar 22, 2026
CVE-2026-33319
5.9
MEDIUM
1 Writeup
AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
CWE-78
Mar 22, 2026
CVE-2026-33296
1 Writeup
AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
CWE-601
Mar 22, 2026
CVE-2026-33295
1 Writeup
AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
CWE-79
Mar 22, 2026
CVE-2026-33294
5.0
MEDIUM
1 Writeup
AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources
CWE-918
Mar 22, 2026
CVE-2026-33293
8.1
HIGH
1 Writeup
AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
CWE-22
Mar 22, 2026
CVE-2026-33292
7.5
HIGH
1 Writeup
AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
CWE-22
Mar 22, 2026
CVE-2026-4553
8.8
HIGH
1 Writeup
Tenda F453 Parameters Natlimit fromNatlimit stack-based overflow
CWE-121
Mar 22, 2026
CVE-2026-4552
8.8
HIGH
1 Writeup
Tenda F453 Parameters VirtualSer fromVirtualSer memory corruption
CWE-121
Mar 22, 2026
CVE-2026-4551
8.8
HIGH
1 Writeup
Tenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption
CWE-121
Mar 22, 2026
CVE-2026-4550
4.7
MEDIUM
1 Writeup
code-projects Simple Gym Management System func.php sql injection
CWE-74
Mar 22, 2026
CVE-2026-4549
3.1
LOW
mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization
CWE-285
Mar 22, 2026
CVE-2026-4548
6.3
MEDIUM
mickasmt next-saas-stripe-starter update-user-role.ts updateUserrole improper authorization
CWE-266
Mar 22, 2026