Exploit Search

PoC Search Engine

AI Enriched

Search specific CVE exploits enriched with AI vulnerability analysis.

Found 32542 Vulnerabilities with Exploits

Path Traversal in ROS#

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack ROS# / ROS#
<V2.2.2
Impact Vector Path Traversal
Authentication Authenticated

Verified Exploits (1)

Unauthenticated RCE via Code Injection in Phoenix Storybook

Severity CRITICAL
9.5

AI Intelligence Analysis

Target Stack phenixdigital / phoenix_storybook
>=0.5.0 <1.1.0
Impact Vector RCE
Authentication PRE-AUTH

Verified Exploits (1)

Stack-based Buffer Overflow in Web Interface

Severity HIGH
7.4

AI Intelligence Analysis

Target Stack Tenda / HG7HG9 and HG10
=300001138_en_xpon
Impact Vector RCE
Authentication PRE-AUTH

Out-of-bounds heap read in Socket.pm

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Perl / Socket
<2.041
Impact Vector Information Disclosure
Authentication PRE-AUTH

Sandbox escape in DOM Navigation

Severity CRITICAL
9.6

AI Intelligence Analysis

Target Stack Mozilla / Thunderbird
<152 <140.12
Impact Vector Sandbox Escape
Authentication PRE-AUTH

Vulnerability in APM - Application Performance Management (JADM, JVM Diagnostics)

Severity CRITICAL
9.1

AI Intelligence Analysis

Target Stack Oracle / APM - Application Performance Management
=13.5 =24.1
Impact Vector Data Tampering, DOS
Authentication PRE-AUTH

Linux Kernel IPC IDR Out-of-Bounds Allocation and Use-After-Free

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Linux Foundation / Linux Kernel
Impact Vector Use-After-Free
Authentication PRE-AUTH

Verified Exploits (1)

External entity resolution allowing local file expansion in Symfony Crawler

Severity HIGH
8.7

AI Intelligence Analysis

Target Stack Symfony / Symfony
<5.4.52 <6.4.40 <7.4.12 <8.0.12
Impact Vector XXE/LFI
Authentication Authenticated

Verified Exploits (1)

HTML Injection leading to XSS due to CSRF cookie escaping issue

Severity HIGH
8.1

AI Intelligence Analysis

Target Stack Litestar / Litestar
<2.20.0
Impact Vector HTML Injection, Cross-Site Scripting (XSS)
Authentication PRE-AUTH

Cleartext Storage of Sensitive Information in Cisco Catalyst SD-WAN

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Cisco / Cisco Catalyst SD-WAN
Impact Vector Information Disclosure
Authentication PRE-AUTH

Improper Input Validation in Cisco Catalyst SD-WAN

Severity CRITICAL
9.9

AI Intelligence Analysis

Target Stack Cisco / Catalyst SD-WAN
Impact Vector
Authentication PRE-AUTH

Improper Access Control in Cisco Catalyst SD-WAN

Severity CRITICAL
9.9

AI Intelligence Analysis

Target Stack Cisco / Catalyst SD-WAN
Impact Vector
Authentication PRE-AUTH

Improper Link Resolution Before File Access in Cisco Catalyst SD-WAN

Severity HIGH
7.7

AI Intelligence Analysis

Target Stack Cisco / Cisco Catalyst SD-WAN
Impact Vector Improper Link Resolution
Authentication PRE-AUTH
CVE-2020-13671 CISA KEV ACTIVE

Filename unsanitized in Drupal core leads to incorrect MIME type or PHP execution

Severity HIGH
8.8

AI Intelligence Analysis

Target Stack Drupal / Drupal Core
<9.0.8 <8.9.9 <8.8.11 <7.74
Impact Vector Arbitrary Code Execution
Authentication Authenticated

ProFTPD mod_sql remote code execution

Severity HIGH
8.1

Linux Kernel tcindex Use After Free Privilege Escalation

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Linux / Kernel
>=4.14 <ee059170b1f7e94e55fa6cadee544e176a6e59c2
Impact Vector Privilege Escalation
Authentication PRE-AUTH

Verified Exploits (1)

Out-of-bounds write in Linux kernel flower classifier

Severity HIGH
7.8

AI Intelligence Analysis

Target Stack Linux kernel / kernel
<6.3.7
Impact Vector DoS/EoP
Authentication PRE-AUTH

Verified Exploits (1)

Reflected XSS in JetEngine

Severity HIGH
7.1

AI Intelligence Analysis

Target Stack Crocoblock / JetEngine
<= 3.7.7
Impact Vector XSS
Authentication PRE-AUTH

Unauthenticated RCE in Grandstream GXP series IP phones

Severity CRITICAL
9.3

AI Intelligence Analysis

Target Stack Grandstream / GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, GXP1630
Impact Vector RCE
Authentication PRE-AUTH

Sandbox escape in Firefox and Thunderbird Storage: IndexedDB component

Severity CRITICAL
10.0

AI Intelligence Analysis

Target Stack Mozilla / Firefox, Firefox ESR, Thunderbird, Thunderbird ESR
<148 <140.8
Impact Vector Sandbox Escape
Authentication PRE-AUTH