Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,495 CVEs tracked 53,335 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,233 vendors 42,833 researchers
42,627 results Clear all
CVE-2012-1600 EPSS 0.01
Phppgadmin < 5.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a function.
CWE-79 May 14, 2014
CVE-2014-3456 EPSS 0.00
Gitlab - XSS
Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 13, 2014
CVE-2013-4503 EPSS 0.00
Feed Element Mapper - XSS
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.
CWE-79 May 13, 2014
CVE-2013-1407 EPSS 0.00
Netweblogic Events Manager < 5.3.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_comment parameter to an event with registration enabled; or the (6) _wpnonce parameter to wp-admin/edit.php.
CWE-79 May 13, 2014
CVE-2013-6454 EPSS 0.00
Mediawiki < 1.19.9 - XSS
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.
CWE-79 May 12, 2014
CVE-2013-6452 EPSS 0.00
Mediawiki < 1.19.9 - XSS
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
CWE-79 May 12, 2014
CVE-2013-5749 EPSS 0.00
Simplerisk < 20130915-001 - XSS
Cross-site scripting (XSS) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to inject arbitrary web script or HTML via the new_project parameter.
CWE-79 May 12, 2014
CVE-2013-4574 EPSS 0.00
MediaWiki <1.19.10, <1.21.4, <1.22.1 - XSS
Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to videos.
CWE-79 May 12, 2014
CVE-2013-6220 EPSS 0.01
HP Network Node Manager I - XSS
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 10, 2014
CVE-2014-0945 EPSS 0.00
IBM Operational Decision Manager - XSS
Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 May 09, 2014
CVE-2014-0913 EPSS 0.00
IBM Lotus Domino - XSS
Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.
CWE-79 May 09, 2014
CVE-2014-2854 EPSS 0.00
Semantictitle - XSS
Cross-site scripting (XSS) vulnerability in the SemanticTitle extension before 1.1.0 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 08, 2014
CVE-2013-5916 EPSS 0.00
Bradesco Gateway - XSS
Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
CWE-79 May 08, 2014
CVE-2014-3207 EPSS 0.00
Sks Keyserver < 1.1.4 - XSS
Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1.
CWE-79 May 08, 2014
CVE-2014-3123 EPSS 0.00
Wpgetready Nextcellent Gallery < 1.9.17 - XSS
Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.
CWE-79 May 08, 2014
CVE-2014-2689 EPSS 0.00
Slashes&dots Offria < 2.1.0 - XSS
Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.
CWE-79 May 08, 2014
CVE-2014-0362 EPSS 0.01
Google Search Appliance <7.0.14.G.216 & <7.2.0.G.114 - XSS
Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inject arbitrary web script or HTML via input included in a SCRIPT element.
CWE-79 May 08, 2014
CVE-2014-2191 EPSS 0.00
Cisco BAC-TW - XSS
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun91113.
CWE-79 May 07, 2014
CVE-2013-6726 EPSS 0.00
IBM Tririga Application Platform - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 07, 2014
CVE-2014-0149 EPSS 0.00
Red Hat JBoss Web Framework Kit 2.5.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.
CWE-79 May 05, 2014