Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 31343 Vulnerabilities with Exploits

Unauthenticated RCE in Custom css-js-php WordPress plugin

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack WordPress / Custom css-js-php plugin
<=2.0.7
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)

TOTP Secret Disclosure in JWS Payload

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack sealed-env / sealed-env
>=0.1.0-alpha.1 <0.1.0-alpha.4
Impact Vector Info Disclosure
Authentication PRE-AUTH

Verified Exploits (1)

Arbitrary Python code execution via Jupyter bypass

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Open WebUI / Open WebUI
<0.8.12
Impact Vector RCE
Authentication PRE-AUTH

Information Exposure in Windows Snipping Tool

Severity MEDIUM
4.3

AI Intelligence Analysis

Target Stack Microsoft / Windows Snipping Tool
Impact Vector vb
Authentication Authenticated

Verified Exploits (1)

XXE in Cisco Catalyst SD-WAN Manager allows arbitrary file read

Severity HIGH
8.6

AI Intelligence Analysis

Target Stack Cisco / Catalyst SD-WAN Manager
Impact Vector Info Disclosure
Authentication PRE-AUTH
CVE-2026-20182 CISA KEV ACTIVE

Authentication Bypass in Cisco Catalyst SD-WAN Controller and Manager

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Cisco / Catalyst SD-WAN Controller and Manager
Impact Vector Authentication Bypass
Authentication PRE-AUTH

PraisonAI Flask API Server Unauthenticated Access

Severity HIGH
7.3

AI Intelligence Analysis

Target Stack PraisonAI / PraisonAI
>=2.5.6 <4.6.34
Impact Vector Unauthorized Access
Authentication PRE-AUTH

Authentication Bypass in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack ePati Cyber Security Technologies Inc. / Antikor Next Generation Firewall (NGFW)
>=2.0.1298 <2.0.1301
Impact Vector Authentication Bypass
Authentication PRE-AUTH

Verified Exploits (1)

Buffer overflow in PJSIP PJNATH ICE Session

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack PJSIP / PJSIP
<=2.16
Impact Vector Buffer Overflow
Authentication PRE-AUTH

WordPress Contact Form by Supsystic SSTI to RCE

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Supsystic / Contact Form by Supsystic plugin for WordPress
<=1.7.36
Impact Vector RCE
Authentication PRE-AUTH

Unauthenticated SSRF and Environment Variable Exfiltration

Severity CRITICAL
9.2

AI Intelligence Analysis

Target Stack MagicMirror² Project / MagicMirror²
<2.36.0
Impact Vector SSRF, Information Disclosure
Authentication Authenticated

Verified Exploits (1)

Missing Authorization in User Registration & Membership

Severity MEDIUM
5.3

AI Intelligence Analysis

Target Stack User Registration & Membership / User Registration & Membership plugin
<=5.1.5
Impact Vector Missing Authorization
Authentication PRE-AUTH

Arbitrary Command Execution in Cockpit UI

Severity HIGH
8.0

AI Intelligence Analysis

Target Stack Cockpit / Cockpit
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)

CVE-2026-45321 CISA KEV ACTIVE

npm package supply chain attack

Severity CRITICAL
9.6

AI Intelligence Analysis

Target Stack TanStack / @tanstack/* packages
Impact Vector Credential Stealing
Authentication PRE-AUTH

Untrusted Pointer Dereference in Windows Kernel

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Microsoft / Windows Kernel
Impact Vector EoP
Authentication Authenticated

Arbitrary File Upload in Ninja Forms - File Uploads

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Ninja Forms / File Uploads plugin for WordPress
<=3.3.26
Impact Vector RCE
Authentication PRE-AUTH

Arbitrary Command Execution via Configuration Files

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Glances / Glances
<4.5.3
Impact Vector RCE, Privilege Escalation
Authentication PRE-AUTH

Verified Exploits (1)

Multipart Request Processing Bug in OWASP CRS

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack OWASP / Core Rule Set (CRS)
< 4.22.0 < 3.3.8
Impact Vector Security Feature Bypass
Authentication PRE-AUTH

Next.js Partial Prerendering Connection Exhaustion DoS

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Next.js / Next.js
<15.5.16
Impact Vector DoS
Authentication PRE-AUTH

Buffer Overflow in NXP moal.ko Wi-Fi driver

Severity MEDIUM
5.6

AI Intelligence Analysis

Target Stack NXP / moal.ko Wi-Fi driver
>=17.92.1.p149.43 <=17.92.1.p149.157
Impact Vector Buffer Overflow
Authentication Authenticated

Verified Exploits (1)