Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 32542 Vulnerabilities with Exploits

Eval Injection to RCE in Langflow eval_custom_component_code

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Langflow / Langflow
Impact Vector RCE
Authentication PRE-AUTH

RCE in QGIS GitHub Actions Workflow

Severity HIGH
8.7

AI Intelligence Analysis

Target Stack QGIS / QGIS
< 76a693cd91650f9b4e83edac525e5e4f90d954e9
Impact Vector RCE
Authentication PRE-AUTH

RCE in Eclipse Theia Website GitHub Actions Workflow

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Eclipse Foundation / Theia Website
Impact Vector RCE
Authentication PRE-AUTH

Authenticated Command Execution in ONT/Beacon unified WEBUI

Severity HIGH
8.0

AI Intelligence Analysis

Target Stack N/A / ONT/Beacon Devices
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Heap Address Leak in vLLM

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack vLLM / vLLM
>= 0.8.3 < 0.14.1
Impact Vector Information Disclosure
Authentication PRE-AUTH

Path traversal in MarkUs assignment zip upload

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack MarkUs / MarkUs
<2.9.1
Impact Vector Path Traversal
Authentication Authenticated

Verified Exploits (1)

RCE in AXIS VAPIX API mediaclip.cgi

Severity HIGH
7.1

AI Intelligence Analysis

Target Stack AXIS / VAPIX API
Impact Vector RCE
Authentication Authenticated

Insecure Deserialization in SPIP table_valeur filter

Severity CRITICAL
9.2

AI Intelligence Analysis

Target Stack SPIP / SPIP
<4.4.9
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

JavaScript injection in LiveCode GitHub Actions workflow

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack LiveCode / LiveCode
<e151c64c2bd80d2d53ac1333f1df9429fe6a1a11
Impact Vector RCE
Authentication Authenticated

OS command injection in WPGraphQL GitHub Actions workflow

Severity HIGH
7.7

AI Intelligence Analysis

Target Stack WPGraphQL / WPGraphQL GitHub Actions
<2.9.1
Impact Vector RCE
Authentication Authenticated

Untrusted code execution in OpenLIT GitHub Actions workflows

Severity CRITICAL
9.9

AI Intelligence Analysis

Target Stack OpenLIT / OpenLIT GitHub Actions
<1.37.1
Impact Vector RCE
Authentication PRE-AUTH

Untrusted code checkout in workflow leads to RCE

Severity HIGH
8.3

AI Intelligence Analysis

Target Stack Mesa / Mesa
<=3.5.0
Impact Vector RCE
Authentication Authenticated

Jellyfin iOS GitHub Actions Workflow RCE

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Jellyfin / jellyfin-ios
Impact Vector RCE, Supply Chain Attack, Repository Takeover
Authentication PRE-AUTH

Arbitrary Code Execution in FastGPT Workflow

Severity CRITICAL
9.4

AI Intelligence Analysis

Target Stack FastGPT / FastGPT
<=4.14.8.3
Impact Vector RCE
Authentication PRE-AUTH

Unauthenticated Remote Shell Injection in GitHub Actions

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Langflow / Langflow GitHub Actions
< 1.9.0
Impact Vector RCE
Authentication PRE-AUTH

Wazuh GitHub Actions GITHUB_TOKEN Exposure

Severity HIGH
8.3

AI Intelligence Analysis

Target Stack Wazuh / Wazuh
=4.12.0
Impact Vector Information Exposure
Authentication Authenticated

Command Injection in wenxian GitHub Actions Workflow

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack wenxian / wenxian
<=0.3.1
Impact Vector RCE
Authentication Authenticated

Shell Command Injection in dbt-labs/actions workflow

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack dbt-labs / actions
Impact Vector RCE
Authentication Authenticated

HTTP Request/Response Smuggling via invalid chunk extension

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Apache / Tomcat
>=11.0.0-M1 <=11.0.18 >=10.1.0-M1 <=10.1.52 >=9.0.0.M1 <=9.0.115 >=8.5.0 <=8.5.100 >=7.0.0 <=7.0.109
Impact Vector HTTP Request Smuggling
Authentication Authenticated

Default Web Security Ineffective Allowing Unauthorized Access

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Spring / Spring Boot
>=4.0.0 <4.0.6
Impact Vector Unauthorized Access
Authentication PRE-AUTH