Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,500 CVEs tracked 53,315 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,254 vendors 42,840 researchers
42,630 results Clear all
CVE-2014-5273 EPSS 0.00
Phpmyadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
CWE-79 Aug 22, 2014
CVE-2010-5303 EPSS 0.00
TimThumb <1.15 - XSS
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.
CWE-79 Aug 21, 2014
CVE-2010-5302 EPSS 0.00
TimThumb <1.15 - XSS
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
CWE-79 Aug 21, 2014
CVE-2009-5142 EPSS 0.00
Binarymoon Timthumb < 1.09 - XSS
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the src parameter.
CWE-79 Aug 21, 2014
CVE-2014-5382 EPSS 0.00
Schrack Technik Microcontrol Firmware - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web script or HTML via the position textbox in the configuration menu or other unspecified vectors.
CWE-79 Aug 20, 2014
CVE-2014-2511 EPSS 0.00
EMC Documentum WebTop <6.7 SP1 P28, <6.7 SP2 P14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.
CWE-79 Aug 20, 2014
CVE-2014-5348 EPSS 0.00
Riverbed Steelapp Traffic Manager - XSS
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.
CWE-79 Aug 19, 2014
CVE-2014-5345 1 PoC Analysis EPSS 0.02
Disqus Comment System < 2.75 - XSS
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
CWE-79 Aug 19, 2014
CVE-2014-5344 EPSS 0.00
Mobiloud < 2.3.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud (mobiloud-mobile-app-plugin) plugin before 2.3.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Aug 19, 2014
CVE-2014-5343 EPSS 0.00
Fengoffice Feng Office - XSS
Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.
CWE-79 Aug 19, 2014
CVE-2014-3903 EPSS 0.00
Cakifo theme <1.6.2 - XSS
Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via crafted Exif data.
CWE-79 Aug 19, 2014
CVE-2014-5240 EPSS 0.01
Wordpress < 3.9.1 - XSS
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
CWE-79 Aug 18, 2014
CVE-2014-3080 1 PoC Analysis EPSS 0.08
IBM Global Console Manager 16 Firmware < 1.20.0.22575 - XSS
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.
CWE-79 Aug 17, 2014
CVE-2014-3905 EPSS 0.00
tenfourzero Shutter 0.1.4 - XSS
Cross-site scripting (XSS) vulnerability in tenfourzero Shutter 0.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 17, 2014
CVE-2014-3900 EPSS 0.00
Piwigo <2.6.3 - XSS
Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.
CWE-79 Aug 17, 2014
CVE-2014-5248 EPSS 0.00
Mybb < 1.6.14 - XSS
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.
CWE-79 Aug 14, 2014
CVE-2012-5684 1 PoC Analysis EPSS 0.09
ZPanel <10.0.1 - XSS
Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/.
CWE-79 Aug 14, 2014
CVE-2014-3898 EPSS 0.00
Fujitsu ServerView Ops Mgr <6.30.05 - XSS
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView Operations Manager 5.00.09 through 6.30.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2014
CVE-2014-1980 EPSS 0.00
Piwigo <2.4.6 - XSS
Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the Make field in IPTC Exif metadata within an image uploaded to the Community plugin.
CWE-79 Aug 14, 2014
CVE-2014-5202 EPSS 0.00
Compfight - XSS
Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.
CWE-79 Aug 12, 2014