Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 32542 Vulnerabilities with Exploits

Agentic Workflow Injection in nnU-Net GitHub workflow

Severity HIGH
7.2

AI Intelligence Analysis

Target Stack nnU-Net / nnU-Net
<2.4.1
Impact Vector Arbitrary_Action_Execution
Authentication PRE-AUTH

DNS Rebinding Attack in rmcp Streamable HTTP server transport

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack RMCP / RMCP
<1.4.0
Impact Vector Unauthorized Access
Authentication PRE-AUTH

Apache Flink SQL Code Injection Arbitrary Code Execution

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack Apache / Flink
>=1.15.0 <1.20.4 >=2.0.0 <2.0.2 >=2.1.0 <2.1.2 >=2.2.0 <2.2.1
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

GitHub Actions RCE via Pull Request

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack CloudPirates / CloudPirates Open Source Helm Charts
Impact Vector RCE
Authentication Authenticated

CoreShop GitHub Actions RCE (Pwn Request)

Severity HIGH
8.2

AI Intelligence Analysis

Target Stack CoreShop / Pimcore enhanced eCommerce solution
>=5.0.1 <=5.1.0-beta.1
Impact Vector RCE
Authentication PRE-AUTH

Quest Bot GitHub Actions Workflow RCE

Severity CRITICAL
9.5

AI Intelligence Analysis

Target Stack Quest Bot / Quest Bot
<1.0.3
Impact Vector RCE
Authentication PRE-AUTH

SQL Injection in Contacts Provider

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Android / Contacts Provider
Impact Vector SQL Injection
Authentication PRE-AUTH

Linux Kernel SCTP Use-After-Free in COOKIE-ECHO Handling

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Linux Foundation / Linux Kernel
Impact Vector Use-After-Free
Authentication Authenticated

Verified Exploits (1)

Remote Code Execution via Forged Upload Metadata in Telerik UI for AJAX

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack Progress / Telerik UI for AJAX
<2026.2.708
Impact Vector RCE
Authentication PRE-AUTH

Decryption Oracle in Telerik RadAsyncUpload

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Progress / Telerik UI for AJAX
<2026.2.708
Impact Vector Information Disclosure
Authentication PRE-AUTH

Timing Attack in Telerik RadAsyncUpload

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Progress / Telerik UI for AJAX
<2026.2.708
Impact Vector Information Disclosure
Authentication PRE-AUTH

Predictable Default Key in Telerik UI for AJAX

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Progress / Telerik UI for AJAX
<2026.2.708
Impact Vector Integrity Bypass
Authentication PRE-AUTH

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert

Severity HIGH
7.1

AI Intelligence Analysis

Target Stack / Popup for CF7 with Sweet Alert
<=1.6.5
Impact Vector CSRF
Authentication Authenticated

Verified Exploits (1)

Cotonti CMS Comments Plugin PHP Object Injection RCE

Severity HIGH
7.6

AI Intelligence Analysis

Target Stack Cotonti / Cotonti CMS
Impact Vector RCE
Authentication PRE-AUTH

Unauthenticated Arbitrary File Upload and RCE in Product Input Fields for WooCommerce

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack N/A / Product Input Fields for WooCommerce
<2.0.2
Impact Vector RCE, Arbitrary File Upload
Authentication Authenticated

Stored Cross-Site Scripting in WP-Stats Plugin

Severity HIGH
7.2

AI Intelligence Analysis

Target Stack WP-Stats / WP-Stats plugin
<=2.56
Impact Vector XSS
Authentication PRE-AUTH

Verified Exploits (1)

CVE-2020-5741 CISA KEV ACTIVE

Plex Media Server Deserialization of Untrusted Data RCE

Severity HIGH
7.2

AI Intelligence Analysis

Target Stack Plex / Plex Media Server
Impact Vector RCE
Authentication Authenticated

PHP Local File Inclusion in Gecko

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack JanStudio / Gecko
<= 1.9.8
Impact Vector LFI
Authentication PRE-AUTH

Verified Exploits (1)

RCE in Eigent CI Workflow

Severity HIGH
8.9

AI Intelligence Analysis

Target Stack Eigent / Eigent
Impact Vector RCE
Authentication PRE-AUTH

Code Injection to RCE in Langflow

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Langflow / Langflow
Impact Vector RCE
Authentication PRE-AUTH