Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 31908 Vulnerabilities with Exploits

Stored Cross-Site Scripting (XSS) in osTicket (email From-header)

Severity MEDIUM
6.1

AI Intelligence Analysis

Target Stack osTicket / osTicket
=1.18.3
Impact Vector Cross-Site Scripting
Authentication PRE-AUTH

Linux Kernel UAF in posix-cpu-timers

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack / Linux kernel
Impact Vector UAF
Authentication Authenticated

MFPs shipped with user authentication disabled by default

Severity MEDIUM
6.9

AI Intelligence Analysis

Target Stack Sharp, Toshiba Tec / MFPs
Impact Vector Information Disclosure, Unauthorized Access
Authentication PRE-AUTH

Verified Exploits (1)

PyAthena SQL Injection

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack PyAthena / PyAthena
<3.35.4
Impact Vector SQLi
Authentication PRE-AUTH

Unauthenticated RCE via Environment Variable Injection in IBM Langflow OSS

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack IBM / Langflow OSS
>=1.0.0 <=1.10.1
Impact Vector RCE
Authentication PRE-AUTH

Arbitrary File Read in WooCommerce Designer Pro theme

Severity HIGH
8.6

AI Intelligence Analysis

Target Stack / WooCommerce Designer Pro theme
<=1.9.28
Impact Vector vb
Authentication PRE-AUTH

Unauthenticated RCE in Realtyna Organic IDX plugin + WPL Real Estate

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Realtyna / Realtyna Organic IDX plugin + WPL Real Estate
<5.3.0
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Privilege Escalation via Account Takeover in FS Registration Password plugin

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack WordPress / FS Registration Password plugin
<=1.0.1
Impact Vector Privilege Escalation, Account Takeover
Authentication Authenticated

Authenticated RCE in n8n workflow creation/modification

Severity CRITICAL
9.4

AI Intelligence Analysis

Target Stack n8n / n8n
<2.10.1 <2.9.3 <1.123.22
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Out-of-Bounds Write in Android IDrmManagerService

Severity HIGH
8.4

AI Intelligence Analysis

Target Stack N/A / Android IDrmManagerService
Impact Vector Privilege Escalation
Authentication PRE-AUTH

Verified Exploits (1)

Stack-based Buffer Overflow in Wavlink WL-NU516U1

Severity HIGH
7.4

AI Intelligence Analysis

Target Stack Wavlink / WL-NU516U1
Impact Vector Buffer Overflow
Authentication Authenticated

Verified Exploits (1)

OpenHands Command Injection

Severity HIGH
7.6

AI Intelligence Analysis

Target Stack OpenHands / OpenHands
Impact Vector Command Injection
Authentication Authenticated

Verified Exploits (1)

Authenticated RCE via arbitrary file creation

Severity HIGH
8.7

AI Intelligence Analysis

Target Stack Wolf CMS / Wolf CMS
<=0.8.3.1
Impact Vector RCE
Authentication Authenticated

Verified Exploits (1)

Linux Kernel rds Zerocopy Send Cleanup Vulnerability

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Linux / Kernel
Impact Vector Denial of Service
Authentication Authenticated

Verified Exploits (1)

Termix File Manager Broken Access Control

Severity CRITICAL
9.0

AI Intelligence Analysis

Target Stack Termix / Termix
<2.3.2
Impact Vector RCE
Authentication Authenticated

Termix File Manager OS command injection via resolvePath

Severity CRITICAL
9.0

AI Intelligence Analysis

Target Stack Termix / Termix
<2.3.2
Impact Vector RCE
Authentication Authenticated

Linux Kernel KVM arm64 vgic-its double free

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack Linux Foundation / Linux Kernel
Impact Vector
Authentication PRE-AUTH

Verified Exploits (1)

Simply Schedule Appointments PII Disclosure & Deletion

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Simply Schedule Appointments / Simply Schedule Appointments WordPress plugin
<1.6.12.6
Impact Vector Information Disclosure
Authentication Authenticated

net/sched: act_api: use RCU with deferred freeing for action lifecycle

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Linux / kernel
Impact Vector Use-After-Free
Authentication Authenticated

Verified Exploits (1)

Kestra Unauthenticated RCE via API Authentication Bypass

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Kestra / Kestra OSS
<1.0.45 <1.3.21
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)