Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,495 CVEs tracked 53,335 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,233 vendors 42,833 researchers
42,627 results Clear all
CVE-2014-2577 EPSS 0.00
Bottomline Technologies Transform Foundation Server <5.2.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3) referer parameter to index.fsp/index.fsp, or (4) PATH_INFO to the default URI.
CWE-79 Jun 05, 2014
CVE-2014-1998 EPSS 0.00
Nippon Institute of Agroinformatics SOY CMS <1.4.0c - XSS
Cross-site scripting (XSS) vulnerability in Nippon Institute of Agroinformatics SOY CMS 1.4.0c and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 05, 2014
CVE-2014-3960 EPSS 0.00
OpenNMS <1.12.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2014
CVE-2014-3949 EPSS 0.00
TYPO3 gridelements <2.0.3 - XSS
Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2014
CVE-2014-3948 EPSS 0.00
TYPO3 powermail <1.6.11 - XSS
Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension before 1.6.11 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2014
CVE-2014-3833 EPSS 0.00
Owncloud < 5.0.15 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before 5.016 and 6.0.x before 6.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.
CWE-79 Jun 04, 2014
CVE-2014-3832 EPSS 0.00
Owncloud Server - XSS
Cross-site scripting (XSS) vulnerability in the Documents component in ownCloud Server 6.0.x before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.
CWE-79 Jun 04, 2014
CVE-2014-3786 EPSS 0.00
Lucidcrew Pixie - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
CWE-79 Jun 04, 2014
CVE-2012-5056 EPSS 0.00
ownCloud Server <4.0.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) readyCallback parameter to apps/files_odfviewer/src/webodf/webodf/flashput/PUT.swf, the (2) root parameter to apps/gallery/templates/index.php, or a (3) malformed query to lib/db.php.
CWE-79 Jun 04, 2014
CVE-2014-2502 EPSS 0.00
EMC RSA Adaptive Authentication (Hosted) 11.0 - XSS
Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA Adaptive Authentication (Hosted) 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 04, 2014
CVE-2014-3959 EPSS 0.01
F5 BIG-IP LTM - XSS
Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1 PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Jun 03, 2014
CVE-2014-3943 EPSS 0.00
TYPO3 <4.5.34-6.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allow remote authenticated editors to inject arbitrary web script or HTML via unknown parameters.
CWE-79 Jun 03, 2014
CVE-2014-2939 EPSS 0.01
Alfresco < 4.1.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.
CWE-79 Jun 02, 2014
CVE-2014-3933 EPSS 0.00
Drupal 7.x-1.x - XSS
Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via an address field.
CWE-79 Jun 02, 2014
CVE-2014-2353 EPSS 0.01
Cogent DataHub <7.3.5 - XSS
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-80 May 30, 2014
CVE-2014-3010 EPSS 0.00
IBM Websphere Service Registry And Repository - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 May 30, 2014
CVE-2014-3924 EPSS 0.01
Webmin <1.690 & Usermin <1.600 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.
CWE-79 May 30, 2014
CVE-2014-3923 EPSS 0.00
WordPress DZS Video Gallery - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or (4) preview_skin_overlay.swf in deploy/.
CWE-79 May 30, 2014
CVE-2014-3922 EPSS 0.01
Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.15...
Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows remote authenticated users to inject arbitrary web script or HTML via the addWhiteListDomainStr parameter to addWhiteListDomain.imss.
CWE-79 May 30, 2014
CVE-2014-3921 EPSS 0.00
Simple Popup Images < - XSS
Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the z parameter.
CWE-79 May 30, 2014