Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 32542 Vulnerabilities with Exploits

Polymorphic type validator bypass via generic type parameters

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack FasterXML / jackson-databind
>=2.10.0 <2.18.8 >=2.21.0 <2.21.4 >=3.0.0 <3.1.4
Impact Vector RCE
Authentication PRE-AUTH
CVE-2026-53266 CISA KEV ACTIVE

netfilter: bridge: make ebt_snat ARP rewrite writable

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Linux / kernel
Impact Vector Data Corruption
Authentication PRE-AUTH

Verified Exploits (1)

D-Link R95 BE9500 OS Command Injection

Severity HIGH
8.5

AI Intelligence Analysis

Target Stack D-Link / R95 BE9500
=1.00.16
Impact Vector OS Command Injection
Authentication Authenticated

Verified Exploits (1)

Dgraph GraphQL DQL Injection

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Dgraph / Dgraph
<25.3.4
Impact Vector DQL Injection
Authentication Authenticated

Broken object level authorization

Severity HIGH
8.7

AI Intelligence Analysis

Target Stack Onlook / Onlook
<=0.2.32
Impact Vector Unauthorized Access/Modification
Authentication Authenticated

Incorrect authorization allows non-admin to obtain admin token

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack JFrog / Artifactory
Impact Vector Privilege Escalation
Authentication PRE-AUTH
CVE-2026-5430 CISA KEV ACTIVE

JWT authentication bypass via algorithm confusion

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack /
Impact Vector Authentication Bypass, Unauthorized Access, Account Takeover
Authentication PRE-AUTH

Verified Exploits (1)

CVE-2026-42018 CISA KEV ACTIVE

Anonymous-user token exposure in JFrog Artifactory

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack JFrog / JFrog Artifactory
Impact Vector Information Disclosure
Authentication PRE-AUTH

Linux kernel sctp: prevent peer transport count overflow OOB write

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Linux / Kernel
Impact Vector Privilege Escalation
Authentication Authenticated

Verified Exploits (1)

Arbitrary File Upload in Gravity Forms plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Gravity Forms / Gravity Forms plugin for WordPress
<=3.1.0.4
Impact Vector Arbitrary File Upload
Authentication Authenticated

Verified Exploits (1)

Arbitrary Shortcode Execution in Forminator Forms

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack / The Forminator Forms – Contact Form, Payment Form & Custom Form Builder
<=1.57.2
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)

Cross-site Scripting (XSS) in Concrete CMS Community Store

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack Concrete CMS / Community Store
<2.7.8
Impact Vector XSS
Authentication Authenticated

Command Injection in D-Link DIR-860LB1 and DIR-868LB1

Severity HIGH
7.4

AI Intelligence Analysis

Target Stack D-Link / DIR-860LB1
=203b01 =203b03
Impact Vector Command Injection
Authentication Authenticated

Insecure Direct Object References in Amelia Booking plugin

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Amelia Booking / Amelia Booking plugin
<=9.1.2
Impact Vector Account Takeover
Authentication Authenticated

Unauthenticated Deserialization Vulnerability

Severity HIGH
7.2

AI Intelligence Analysis

Target Stack OpenSTAManager / OpenSTAManager
<2.10.2
Impact Vector RCE
Authentication PRE-AUTH

HTTP/1.1 Request Smuggling via chunk extensions

Severity HIGH
7.4

AI Intelligence Analysis

Target Stack Eclipse / Jetty
Impact Vector Request Smuggling
Authentication PRE-AUTH

Skim Remote Code Execution via GitHub Actions workflow

Severity HIGH
7.4

AI Intelligence Analysis

Target Stack Skim / Skim
Impact Vector RCE
Authentication PRE-AUTH

PredatorSense Local Privilege Escalation

Severity HIGH
8.5

AI Intelligence Analysis

Target Stack PredatorSense / PredatorSense
>=3.00.3136 <=3.00.3196
Impact Vector LPE, RCE, file deletion
Authentication Authenticated

Verified Exploits (1)

RCE in Postiz PR Docker Image workflow

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Postiz / AI social media scheduling tool (Build and Publish PR Docker Image workflow)
Impact Vector RCE
Authentication Authenticated

Unauthenticated Privilege Escalation in Grav Login Plugin

Severity CRITICAL
9.4

AI Intelligence Analysis

Target Stack Grav / Grav
<2.0.0-beta.2
Impact Vector Privilege Escalation
Authentication PRE-AUTH

Verified Exploits (1)