Exploit Intelligence Platform

Updated 32m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,500 CVEs tracked 53,315 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,254 vendors 42,840 researchers
42,630 results Clear all
CVE-2014-5103 EPSS 0.00
Zohocorp Manageengine Eventlog Analyzer - XSS
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.
CWE-79 Jul 25, 2014
CVE-2014-5101 1 PoC Analysis EPSS 0.01
Webid - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authnet_id, (12) TPL_authnet_pass, (13) TPL_worldpay_id, (14) TPL_toocheckout_id, or (15) TPL_moneybookers_email in a first action to register.php or the (16) username parameter in a login action to user_login.php.
CWE-79 Jul 25, 2014
CVE-2014-5027 EPSS 0.01
Reviewboard Review Board - XSS
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.
CWE-79 Jul 25, 2014
CVE-2014-5024 EPSS 0.01
Sonicwall Analyzer < 7.2 - XSS
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.
CWE-79 Jul 24, 2014
CVE-2014-3110 1 PoC Analysis EPSS 0.02
Honeywell Falcon Xlweb Linux Controller < 2.04.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.
CWE-79 Jul 24, 2014
CVE-2014-2971 EPSS 0.01
Micropact Icomplaints - XSS
Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remote authenticated users to inject arbitrary web script or HTML via the description parameter.
CWE-79 Jul 24, 2014
CVE-2014-2968 EPSS 0.00
Huawei E355 Web UI - XSS
Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.
CWE-79 Jul 24, 2014
CVE-2014-2370 EPSS 0.01
Omron NS5-NS15 HMI <8.68x - XSS
Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
CWE-79 Jul 24, 2014
CVE-2014-5022 EPSS 0.00
Drupal - XSS
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
CWE-79 Jul 22, 2014
CVE-2014-5021 EPSS 0.00
Drupal - XSS
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
CWE-79 Jul 22, 2014
CVE-2014-2385 EPSS 0.01
Sophos Anti-Virus for Linux <9.6.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.
CWE-79 Jul 22, 2014
CVE-2014-5016 EPSS 0.00
Limesurvey - XSS
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to application/views/admin/globalSettings_view.php, or (3) a crafted CSV file to the "Import CSV" functionality.
CWE-79 Jul 21, 2014
CVE-2014-4734 EPSS 0.00
e107 <2.0 alpha2 - XSS
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
CWE-79 Jul 21, 2014
CVE-2014-4986 EPSS 0.00
phpMyAdmin <4.0.10.1, <4.1.14.2, <4.2.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.
CWE-79 Jul 20, 2014
CVE-2014-4955 EPSS 0.00
phpMyAdmin <4.0.10.1-4.2.6 - XSS
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.
CWE-79 Jul 20, 2014
CVE-2014-4954 EPSS 0.00
phpMyAdmin <4.2.6 - XSS
Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.
CWE-79 Jul 20, 2014
CVE-2014-3894 EPSS 0.00
PHP Kobo Multifunctional MailForm Free <2014-01-28 - XSS
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header.
CWE-79 Jul 20, 2014
CVE-2014-3892 EPSS 0.00
Nexa Meridian <2014 - XSS
Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 20, 2014
CVE-2014-3886 EPSS 0.00
Webmin < 1.680 - XSS
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
CWE-79 Jul 20, 2014
CVE-2014-3885 EPSS 0.00
Webmin < 1.680 - XSS
Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
CWE-79 Jul 20, 2014