Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,484 CVEs tracked 53,337 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,229 vendors 42,825 researchers
42,625 results Clear all
CVE-2013-0805 EPSS 0.00
iTop <2.0-1.2.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 20, 2014
CVE-2014-1971 1 Writeup EPSS 0.00
Silex <2.0.0 - XSS
Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 20, 2014
CVE-2013-5955 EPSS 0.00
Purplebeanie Com Pbbooking - XSS
Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the an arbitrary parameter in an edit action to administrator/index.php.
CWE-79 Mar 19, 2014
CVE-2013-5953 EPSS 0.00
Codepeople Com Multicalendar < 4.8.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) calid or (2) paletteDefault parameter in an editevent action to index.php.
CWE-79 Mar 19, 2014
CVE-2013-5952 EPSS 0.00
Codologic Com Freichat < 9.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php.
CWE-79 Mar 19, 2014
CVE-2014-2120 6.1 MEDIUM KEV EPSS 0.64
Cisco ASA - XSS
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
CWE-79 Mar 19, 2014
CVE-2013-2643 1 PoC Analysis EPSS 0.01
Sophos Web Appliance <3.7.8.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to end-user/ftp_redirect.php, or (4) threat parameter to the Blocked component.
CWE-79 Mar 18, 2014
CVE-2013-0201 1 Writeup EPSS 0.00
Owncloud < 4.0.10 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/templates/resetpassword.php, (2) mime parameter to apps/files/ajax/mimeicon.php, or (3) token parameter to apps/gallery/sharing.php.
CWE-79 Mar 18, 2014
CVE-2012-5650 EPSS 0.01
Apache CouchDB <1.0.4, <1.1.2, <1.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.
CWE-79 Mar 18, 2014
CVE-2014-2246 EPSS 0.01
Siemens SIMATIC S7-1500 <1.5.0 - XSS
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 16, 2014
CVE-2014-1701 EPSS 0.00
Blink <33.0.1750.149 - XSS
The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.
CWE-79 Mar 16, 2014
CVE-2014-0850 EPSS 0.00
IBM Infosphere Master Data Management... - XSS
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 16, 2014
CVE-2014-0339 EPSS 0.01
Webmin <1.680 - XSS
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Mar 16, 2014
CVE-2014-0338 EPSS 0.02
WatchGuard Fireware XTM <11.8.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.
CWE-79 Mar 16, 2014
CVE-2013-4059 EPSS 0.00
IBM Infosphere Information Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces.
CWE-79 Mar 16, 2014
CVE-2013-2150 EPSS 0.00
Owncloud Server < 4.5.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to shared files.
CWE-79 Mar 14, 2014
CVE-2013-2149 EPSS 0.00
Owncloud < 4.0.16 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to shared files.
CWE-79 Mar 14, 2014
CVE-2013-2042 EPSS 0.00
Owncloud < 4.0.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the url parameter to (1) apps/bookmarks/ajax/addBookmark.php or (2) apps/bookmarks/ajax/editBookmark.php.
CWE-79 Mar 14, 2014
CVE-2013-2041 EPSS 0.00
Owncloud Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tag parameter to apps/bookmarks/ajax/addBookmark.php or (2) dir parameter to apps/files/ajax/newfile.php, which is passed to apps/files/js/files.js.
CWE-79 Mar 14, 2014
CVE-2013-2040 EPSS 0.00
Owncloud < 4.0.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 14, 2014