Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,501 CVEs tracked 53,335 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,234 vendors 42,835 researchers
42,628 results Clear all
CVE-2014-4853 EPSS 0.00
OpenDocMan <1.2.7.3 - XSS
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file.
CWE-79 Jul 10, 2014
CVE-2014-4849 EPSS 0.00
FoeCMS - XSS
Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter.
CWE-79 Jul 10, 2014
CVE-2014-4848 EPSS 0.00
WordPress Blogstand Banner <1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bs_blog_id parameter to wp-admin/options-general.php.
CWE-79 Jul 10, 2014
CVE-2014-4847 EPSS 0.00
WordPress Random Banner 1.1.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the buffercode_RBanner_url_banner1 parameter in an update action to wp-admin/options.php.
CWE-79 Jul 10, 2014
CVE-2014-4846 EPSS 0.00
Meta Slider 2.5 - XSS
Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.
CWE-79 Jul 10, 2014
CVE-2014-4845 EPSS 0.00
BannerMan 0.2.4 - XSS
Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bannerman_background parameter to wp-admin/options-general.php.
CWE-79 Jul 10, 2014
CVE-2014-3315 EPSS 0.00
Cisco Unified Communications Manager - XSS
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCup76308.
CWE-79 Jul 10, 2014
CVE-2014-2963 EPSS 0.01
Liferay Portal - XSS
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.
CWE-79 Jul 10, 2014
CVE-2014-4744 EPSS 0.00
osTicket <1.9.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.
CWE-79 Jul 09, 2014
CVE-2014-4743 EPSS 0.00
Kajona <4.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tpl and (2) search_ajax_small.tpl in templates/default/tpl/module_search/ in the Search module (module_search) in Kajona before 4.5 allow remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Jul 09, 2014
CVE-2014-4742 EPSS 0.00
Kajona <4.5 - XSS
Cross-site scripting (XSS) vulnerability in system/class_link.php in the System module (module_system) in Kajona before 4.5 allows remote attackers to inject arbitrary web script or HTML via the systemid parameter in a mediaFolder action to index.php.
CWE-79 Jul 09, 2014
CVE-2014-3313 EPSS 0.00
Cisco Spa 301 1 Line IP Phone - XSS
Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.
CWE-79 Jul 09, 2014
CVE-2014-4724 EPSS 0.00
WordPress Custom Banners <1.2.2.2 - XSS
Cross-site scripting (XSS) vulnerability in the Custom Banners plugin 1.2.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.
CWE-79 Jul 07, 2014
CVE-2014-4723 EPSS 0.00
WordPress Easy Banners 1.4 - XSS
Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter to wp-admin/options-general.php.
CWE-79 Jul 07, 2014
CVE-2014-4722 EPSS 0.00
OCS Inventory NG - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 07, 2014
CVE-2014-0176 EPSS 0.00
CloudForms 3.0 Management Engine <5.2.4.2 - XSS
Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 07, 2014
CVE-2013-7389 EXPLOITED 3 PoCs Analysis EPSS 0.92
D-Link DIR-645 Router - XSS
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid parameter to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3) receiver parameter to bsc_sms_send.php.
CWE-79 Jul 07, 2014
CVE-2014-0870 1 PoC Analysis EPSS 0.09
IBM Algo Credit Limits - XSS
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.
CWE-79 Jul 07, 2014
CVE-2014-3497 EPSS 0.00
Openstack Swift < 2.0.0 - XSS
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
CWE-79 Jul 03, 2014
CVE-2014-4719 EPSS 0.00
User-Friendly SVN <1.0.7 - XSS
Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the username field.
CWE-79 Jul 03, 2014