Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,484 CVEs tracked 53,337 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,229 vendors 42,825 researchers
42,625 results Clear all
CVE-2013-4795 EPSS 0.01
Review Board <1.6.18, <1.7.12 - XSS
Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script or HTML via a user full name.
CWE-79 Apr 11, 2014
CVE-2013-7365 EPSS 0.00
SAP Enterprise Portal - XSS
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Apr 10, 2014
CVE-2012-6132 EPSS 0.00
Roundup < 1.4.19 - XSS
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.
CWE-79 Apr 10, 2014
CVE-2014-0331 EPSS 0.00
FortiADC <3.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale parameter to gui_partA/.
CWE-79 Apr 10, 2014
CVE-2013-2033 EPSS 0.00
Jenkins < 1.509.1 - XSS
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 10, 2014
CVE-2014-0509 EPSS 0.01
Adobe Flash Player < 4.0.0.1390 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 08, 2014
CVE-2014-2542 EPSS 0.00
Tibco Rendezvous < 8.4.1 - XSS
Cross-site scripting (XSS) vulnerability in the Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and Substation ES before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 08, 2014
CVE-2012-6645 EPSS 0.01
Danielb Finder - XSS
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561.
CWE-79 Apr 08, 2014
CVE-2012-6644 8 PoCs Analysis EPSS 0.05
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
CWE-79 Apr 08, 2014
CVE-2012-6642 EPSS 0.00
Clip-bucket Clipbucket - XSS
Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 08, 2014
CVE-2012-1561 EPSS 0.01
Danielb Finder - XSS
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities."
CWE-79 Apr 08, 2014
CVE-2011-4958 1 PoC Analysis EPSS 0.09
Silverstripe < 2.3.12 - XSS
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
CWE-79 Apr 08, 2014
CVE-2012-6641 EPSS 0.00
Prestashop < 1.4.7.1 - XSS
Cross-site scripting (XSS) vulnerability in redirect.php in the Socolissimo module (modules/socolissimo/) in PrestaShop before 1.4.7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to "parameter names and values."
CWE-79 Apr 07, 2014
CVE-2012-1834 EPSS 0.00
Cms Tree Page View < 0.8.8 - XSS
Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.
CWE-79 Apr 07, 2014
CVE-2012-6640 1 Writeup EPSS 0.00
Horde Groupware < 4.0.8 - XSS
Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted SVG image attachment, a different vulnerability than CVE-2012-5565.
CWE-79 Apr 05, 2014
CVE-2012-5567 1 Writeup EPSS 0.01
Horde Kronolith Calendar Application H4 <3.0.18 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.
CWE-79 Apr 05, 2014
CVE-2012-5566 1 Writeup EPSS 0.01
Horde Kronolith Calendar Application H4 <3.0.17 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view.
CWE-79 Apr 05, 2014
CVE-2012-5565 EPSS 0.00
Horde IMP <5.0.24 - XSS
Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.
CWE-79 Apr 05, 2014
CVE-2014-0827 EPSS 0.00
IBM Optim Workload Replay - XSS
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Workload Replay 1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Apr 05, 2014
CVE-2014-0337 EPSS 0.00
Huawei Echo Life HG8247 <V100R006C00SPC127 - XSS
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted username that is not properly handled during construction of the "failed log-in attempts over telnet" log view.
CWE-79 Apr 05, 2014