Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 32542 Vulnerabilities with Exploits

Use-after-free in QEMU 9pfs leading to VM escape

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack QEMU / QEMU
Impact Vector Use-After-Free / RCE / VM Escape
Authentication Authenticated

Verified Exploits (1)

Arbitrary File Upload in Request a Quote for WooCommerce plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack WordPress / Request a Quote for WooCommerce plugin
<=2.9.2
Impact Vector Arbitrary File Upload, RCE
Authentication PRE-AUTH

Verified Exploits (1)

Unauthenticated Remote Code Execution in REDCap

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack REDCap / REDCap
>=13.3.0
Impact Vector RCE
Authentication Authenticated

Apache Tomcat HTTP/2 Request Smuggling

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Apache / Tomcat
>=11.0.22 <=11.0.25 >=10.1.55 <=10.1.59 >=9.0.118 <=9.0.121
Impact Vector Request Smuggling
Authentication PRE-AUTH

Verified Exploits (1)

Sudo authorization bypass via TZ environment variable

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack sudo / sudo
Impact Vector Authorization Bypass
Authentication PRE-AUTH

Cross-Site Request Forgery (CSRF) in Elementor Website Builder

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Elementor / Elementor Website Builder
<=4.3.1
Impact Vector CSRF
Authentication PRE-AUTH

Verified Exploits (1)

API Authentication Method Manipulation Leading to Account Takeover

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack GLPI / GLPI
>=0.70 <10.0.26 <11.0.8
Impact Vector Account Takeover, Privilege Escalation
Authentication Authenticated

SQL Injection via History Tab URL

Severity HIGH
7.1

AI Intelligence Analysis

Target Stack GLPI / GLPI
>=9.4.0 <10.0.26 <11.0.8
Impact Vector SQL Injection, Information Disclosure
Authentication Authenticated

Verified Exploits (1)

Unauthenticated Remote Code Execution

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack D-Link / DAP-1360
<=6.14
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)

Use-after-free in librsvg

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack librsvg / librsvg
Impact Vector DoS, RCE
Authentication PRE-AUTH

Verified Exploits (1)

Privilege Escalation in Automation Web Platform Notifications and OTP for WooCommerce plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Automation Web Platform / Notifications and OTP for WooCommerce, Advanced Country Code
<=4.8.6
Impact Vector Privilege Escalation
Authentication PRE-AUTH

Verified Exploits (1)

Authorization Bypass Media Deletion

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Customer Reviews for WooCommerce / Customer Reviews for WooCommerce plugin
<=5.120.0
Impact Vector Authorization Bypass
Authentication Authenticated

Verified Exploits (1)

Bookly WordPress Plugin Insecure Direct Object Reference

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Bookly / Bookly plugin for WordPress
<=28.2
Impact Vector IDOR/Information Disclosure/Data Deletion
Authentication PRE-AUTH

Verified Exploits (1)

Prompt injection leading to RCE in Decepticon

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Decepticon / Decepticon
<1.1.17
Impact Vector RCE
Authentication PRE-AUTH

Visual Composer WordPress Plugin Local File Inclusion (LFI)

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Visual Composer / Visual Composer Website Builder
<=45.16.0
Impact Vector LFI
Authentication PRE-AUTH

Arbitrary Shortcode Execution in WP Recipe Maker

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack / WP Recipe Maker
<=10.8.1
Impact Vector RCE
Authentication PRE-AUTH

Stored XSS in Ninja Forms Legacy Submission Editor

Severity HIGH
7.2

AI Intelligence Analysis

Target Stack Ninja Forms / Ninja Forms
<=3.15.3
Impact Vector Stored XSS
Authentication Authenticated

Verified Exploits (1)

Authentication Bypass in EthPress Web3 Login for WordPress

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack EthPress / Web3 Login plugin for WordPress
<=2.3.5
Impact Vector Auth Bypass
Authentication Authenticated
CVE-2026-87902 CISA KEV ACTIVE

Remote Code Execution via arbitrary file inclusion

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack /
Impact Vector RCE
Authentication PRE-AUTH
CVE-2026-93616 CISA KEV ACTIVE

Unauthenticated RCE via Directory Traversal and File Upload in Check Point Management Server

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Check Point / Management Server
Impact Vector RCE, Directory Traversal, File Upload
Authentication Authenticated