Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 31342 Vulnerabilities with Exploits

Unrestricted File Upload leading to RCE in PHPPageBuilder

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack Falco Solutions / PHPPageBuilder
=0.31.0
Impact Vector RCE, Arbitrary File Upload
Authentication PRE-AUTH

SSH Brute-Force due to Lack of Rate-Limiting

Severity HIGH
8.7

AI Intelligence Analysis

Target Stack Archer / C64
=v1
Impact Vector Brute-Force, Administrative Access
Authentication Authenticated

Verified Exploits (1)

WordPress WPCode Plugin Remote Code Execution

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack WordPress / WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin
<=2.3.5
Impact Vector RCE
Authentication PRE-AUTH

EspoCRM Authenticated Server-Side Request Forgery (SSRF)

Severity MEDIUM
4.3

AI Intelligence Analysis

Target Stack EspoCRM / EspoCRM
<=9.3.3
Impact Vector SSRF
Authentication Authenticated

Verified Exploits (1)

Unauthenticated OS Command Injection

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack MeiG Smart / FORGE_SLT711
=MDM9607.LE.1.0-00110-STD.PROD-1
Impact Vector RCE
Authentication PRE-AUTH

Arbitrary PHP Code Execution in Documentation Generation

Severity CRITICAL
9.4

AI Intelligence Analysis

Target Stack Scramble / Scramble
>=0.13.2 <0.13.22
Impact Vector RCE
Authentication PRE-AUTH

Casdoor Arbitrary File Write via Path Traversal

Severity MEDIUM
5.9

AI Intelligence Analysis

Target Stack Casdoor / Casdoor Local File System storage provider
Impact Vector Arbitrary File Write
Authentication Authenticated

Verified Exploits (1)

Missing Access Control in Wi-Fi kernel driver

Severity HIGH
7.7

AI Intelligence Analysis

Target Stack Realtek / rtl819x Jungle SDK
<=3.4.14B
Impact Vector Privilege Escalation
Authentication Authenticated

Sherlock GitHub Actions Command Injection

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack Sherlock / Sherlock
<0.16.1
Impact Vector Command Injection
Authentication PRE-AUTH

Verified Exploits (1)

FacturaScripts Authenticated Unrestricted File Upload RCE

Severity MEDIUM
6.3

AI Intelligence Analysis

Target Stack FacturaScripts / FacturaScripts
<=2025.81
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Command Injection and Arbitrary Code Execution in Raynet rvia

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Raynet / rvia
=12.6.4392.49
Impact Vector RCE
Authentication PRE-AUTH

Raynet rvia Command Injection

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Raynet / rvia
<=12.6 Update 8
Impact Vector RCE
Authentication PRE-AUTH

CSRF in Jason2605 AdminPanel delete.php

Severity MEDIUM
6.3

AI Intelligence Analysis

Target Stack Jason2605 / AdminPanel
4.0
Impact Vector CSRF
Authentication Authenticated

Missing Authorization in Craft CMS migrate endpoint

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack Craft CMS / Craft CMS
<=5.9.5
Impact Vector Missing Authorization
Authentication PRE-AUTH

Host Header Validation Bypass in Starlette

Severity MEDIUM
6.5

AI Intelligence Analysis

Target Stack Starlette / Starlette
<1.0.1
Impact Vector Security Bypass
Authentication PRE-AUTH

Double Free leading to RCE in Apache HTTP Server with HTTP/2

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Apache / HTTP Server
=2.4.66
Impact Vector RCE
Authentication PRE-AUTH

Authenticated RCE in Grav Direct Install

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Grav / Grav
<2.0.0-beta.2
Impact Vector RCE, Web Shell
Authentication Authenticated

Verified Exploits (1)

WordPress Temporary Login Plugin Authentication Bypass

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack WordPress / Temporary Login plugin
<=1.0.0
Impact Vector Authentication Bypass
Authentication Authenticated

Code Injection in PbootCMS site configuration functionality

Severity MEDIUM
4.3

AI Intelligence Analysis

Target Stack PbootCMS / PbootCMS
=3.2.11
Impact Vector Code Injection
Authentication PRE-AUTH

Verified Exploits (1)

Unauthenticated XAR import in XWiki Platform

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack XWiki / Platform
<18.1.0-rc-1 <17.10.3 <17.4.9 <16.10.17
Impact Vector Privilege Escalation
Authentication PRE-AUTH