Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 31342 Vulnerabilities with Exploits

Linux kernel cifs.spnego key description bypass

Severity HIGH
7.1

AI Intelligence Analysis

Target Stack Linux / kernel
Impact Vector Privilege Escalation
Authentication Authenticated

Kimi AI: Cross-Site Scripting in Preview feature

Severity MEDIUM
6.3

AI Intelligence Analysis

Target Stack Kimi AI / Kimi AI web interface
==1.0
Impact Vector XSS/Arbitrary JavaScript Execution
Authentication PRE-AUTH

Verified Exploits (1)

Cross-Site Scripting (XSS) via Social Media Links

Severity CRITICAL
9.0

AI Intelligence Analysis

Target Stack RockRMS / RockRMS
<=16.13 <17.7.0
Impact Vector XSS
Authentication Authenticated

Verified Exploits (1)

Totolink N300RH setWiFiBasicConfig Buffer Overflow

Severity HIGH
8.9

AI Intelligence Analysis

Target Stack Totolink / N300RH
=6.1c.1353_B20190305
Impact Vector Stack-based Buffer Overflow
Authentication PRE-AUTH

Verified Exploits (1)

Stack-based Buffer Overflow in BGP AS_PATH

Severity MEDIUM
6.3

AI Intelligence Analysis

Target Stack CZ.NIC / BIRD Internet Routing Daemon
<=2.19.0
Impact Vector Denial of Service
Authentication PRE-AUTH

Go x509.Certificate.VerifyHostname Quadratic Scaling with Large DNS SANs

Severity MEDIUM
6.5

AI Intelligence Analysis

Target Stack Go / x509
Impact Vector Denial of Service
Authentication PRE-AUTH

Verified Exploits (1)

CVE-2025-48595 CISA KEV ACTIVE

Code execution due to integer overflow

Severity HIGH
8.4

AI Intelligence Analysis

Target Stack /
Impact Vector EoP
Authentication Authenticated

Verified Exploits (1)

Automad Broken Access Control

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Automad / Automad
>=2.0.0-alpha.1 <=2.0.0-beta.27
Impact Vector Broken Access Control
Authentication Authenticated

Persistent XSS via unsanitized SQL query editor in Appsmith

Severity MEDIUM
6.3

AI Intelligence Analysis

Target Stack Appsmith / Appsmith
Impact Vector XSS, Arbitrary Code Execution
Authentication Authenticated

Improper access control in PCTCore64.sys allows privilege escalation

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack PC Tools / PCTCore64.sys Windows kernel driver
Impact Vector Privilege Escalation
Authentication Authenticated

Verified Exploits (1)

CVE-2026-9082 CISA KEV ACTIVE

SQL Injection in Drupal core

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack Drupal / Drupal core
>=8.9.0,<10.4.10 >=10.5.0,<10.5.10 >=10.6.0,<10.6.9 >=11.0.0,<11.1.10 >=11.2.0,<11.2.12 >=11.3.0,<11.3.10
Impact Vector SQLi
Authentication PRE-AUTH

Hotel and Tourism Reservation System SQL Injection

Severity MEDIUM
5.5

AI Intelligence Analysis

Target Stack code-projects / Hotel and Tourism Reservation System
=1.0
Impact Vector SQLi
Authentication PRE-AUTH

Improper Authentication in Hotel and Tourism Reservation System

Severity MEDIUM
5.5

AI Intelligence Analysis

Target Stack code-projects / Hotel and Tourism Reservation System
=1.0
Impact Vector Improper Authentication
Authentication Authenticated

Cross Site Scripting in Hotel and Tourism Reservation System

Severity LOW
2.1

AI Intelligence Analysis

Target Stack code-projects / Hotel and Tourism Reservation System
=1.0
Impact Vector XSS
Authentication Authenticated

Privilege Escalation in WP Maps Pro plugin via Admin Account Creation

Severity CRITICAL
9.8

AI Intelligence Analysis

Target Stack WP Maps Pro Plugin Developer / WP Maps Pro plugin
<=6.1.0
Impact Vector Privilege Escalation, Site Takeover
Authentication PRE-AUTH

Unauthenticated SQL Injection and Authentication Bypass

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack OTRS / ((OTRS)) Community Edition
6.0.x
Impact Vector SQLi, Authentication Bypass
Authentication PRE-AUTH

Verified Exploits (1)

Denial of Service via SVG content

Severity MEDIUM
6.5

AI Intelligence Analysis

Target Stack OTRS / ((OTRS)) Community Edition
<=6.x
Impact Vector DoS
Authentication PRE-AUTH

Verified Exploits (1)

Missing Authentication in code-projects Smart Parking System

Severity MEDIUM
5.5

AI Intelligence Analysis

Target Stack code-projects / Smart Parking System
==1.0
Impact Vector Missing Authentication
Authentication PRE-AUTH

Privilege Escalation in OpenVPN Connect for macOS

Severity CRITICAL
9.4

AI Intelligence Analysis

Target Stack OpenVPN / OpenVPN Connect
>=3.5.1 <=3.8.1
Impact Vector Privilege Escalation, RCE
Authentication Authenticated

SQL Injection in Tutor LMS WordPress Plugin

Severity HIGH
7.5

AI Intelligence Analysis

Target Stack Tutor LMS / Tutor LMS – eLearning and online course solution
<=3.9.6
Impact Vector SQLi
Authentication PRE-AUTH

Verified Exploits (1)