Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 31342 Vulnerabilities with Exploits

Windows Cloud Files Mini Filter Driver Elevation of Privilege

Severity HIGH
7.0

AI Intelligence Analysis

Target Stack Microsoft / Windows Cloud Files Mini Filter Driver
Impact Vector Privilege Escalation
Authentication PRE-AUTH

NGINX: HTTP rewrite module heap buffer overflow

Severity CRITICAL
9.2

Intelbras VIP-1230-D-G4 Sensitive Information Disclosure

Severity MEDIUM
5.3

AI Intelligence Analysis

Target Stack Intelbras / VIP-1230-D-G4
=V2.800.00IB00C.0.T
Impact Vector Info Leak
Authentication Authenticated

Verified Exploits (1)

SQL Injection in WP Photo Album Plus

Severity HIGH
8.6

AI Intelligence Analysis

Target Stack WordPress / WP Photo Album Plus plugin
<9.1.11.001
Impact Vector SQLi
Authentication Authenticated

Verified Exploits (1)

RCE in Microsoft Windows DNS

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Microsoft / Windows DNS
Impact Vector RCE
Authentication PRE-AUTH

Authentication Bypass and Privilege Escalation in Burst Statistics WordPress plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Burst Statistics / Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin
>=3.4.0 <=3.4.1.1
Impact Vector Authentication Bypass, Privilege Escalation
Authentication PRE-AUTH

OS command injection in InSAT MasterSCADA BUK-TS

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack InSAT / MasterSCADA BUK-TS
Impact Vector RCE
Authentication Authenticated

DLL Search Order Hijacking in Thermalright TR-VISION HOME

Severity HIGH
8.4

AI Intelligence Analysis

Target Stack Thermalright / TR-VISION HOME
<=2.0.5
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Stored Cross-Site Scripting (XSS) in Panorama Viewer

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack immich / immich
<2.7.0
Impact Vector XSS
Authentication Authenticated

Type Confusion in V8

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Google / Chrome
<147.0.7727.55
Impact Vector RCE
Authentication Authenticated

Authenticated File Upload in Krayin CRM

Severity CRITICAL
9.9

AI Intelligence Analysis

Target Stack Webkul Krayin / CRM
>=2.2.0
Impact Vector RCE
Authentication Authenticated

LMDeploy Server-Side Request Forgery (SSRF)

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack / LMDeploy
<0.12.3
Impact Vector Server-Side Request Forgery (SSRF)
Authentication PRE-AUTH

Unsafe deserialization in ProtoStream remote aggregation repository

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack / camel-infinispan
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Arbitrary File Upload in User Registration Advanced Fields plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack User Registration Advanced Fields / User Registration Advanced Fields plugin for WordPress
<=1.6.20
Impact Vector Arbitrary File Upload
Authentication PRE-AUTH

Authentication Bypass in User Verification by PickPlugins plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack PickPlugins / User Verification by PickPlugins plugin for WordPress
<=2.0.46
Impact Vector Authentication Bypass
Authentication PRE-AUTH

Verified Exploits (1)

Time-Based SQL Injection in Geo Mashup (sort parameter)

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Geo Mashup / Geo Mashup
<=1.13.18
Impact Vector Time-Based SQL Injection
Authentication Authenticated

Memory Exhaustion via Remote Read Endpoint

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Prometheus / Prometheus (remote read endpoint)
<3.5.3 <3.11.3
Impact Vector DoS
Authentication PRE-AUTH

Remote Code Execution via Template Injection in LiteLLM

Severity HIGH
8.6

AI Intelligence Analysis

Target Stack LiteLLM / LiteLLM
>=1.80.5 <1.83.7
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Next.js Server-Side Request Forgery

Severity HIGH
8.6

AI Intelligence Analysis

Target Stack Next.js / Next.js
>=13.4.13 <15.5.16 <16.2.5
Impact Vector SSRF
Authentication PRE-AUTH

Unauthenticated RCE in Custom css-js-php WordPress plugin

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack WordPress / Custom css-js-php plugin
<=2.0.7
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)