Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,480 CVEs tracked 53,336 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,227 vendors 42,821 researchers
42,625 results Clear all
CVE-2014-2035 EPSS 0.00
InterWorx Web Control Panel <5.0.13 - XSS
Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.13 build 574 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
CWE-79 Feb 27, 2014
CVE-2014-1223 EPSS 0.00
Telligent Evolution < 6.1.19.36103 - XSS
Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 27, 2014
CVE-2014-0046 EPSS 0.00
Ember.js <1.2.2-1.4.0-beta.6 - XSS
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title attribute.
CWE-79 Feb 27, 2014
CVE-2014-1968 EPSS 0.00
Xoops XooNIps <3.47 - XSS
Cross-site scripting (XSS) vulnerability in the XooNIps module 3.47 and earlier for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 27, 2014
CVE-2011-4580 EPSS 0.00
Redhat Jboss Enterprise Portal Platform < 5.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 26, 2014
CVE-2014-0853 EPSS 0.00
IBM Rational Focal Point - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 26, 2014
CVE-2014-0843 EPSS 0.00
IBM Rational Focal Point - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
CWE-79 Feb 26, 2014
CVE-2014-0840 EPSS 0.00
IBM Rational Focal Point - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 26, 2014
CVE-2013-6047 EPSS 0.00
Ikiwiki Hosting < 0.20130926 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 25, 2014
CVE-2014-0861 EPSS 0.00
IBM Cognos Business Intelligence - XSS
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.
CWE-79 Feb 22, 2014
CVE-2014-0811 EPSS 0.00
Blackboard Vista/ce < 8.0 - XSS
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 22, 2014
CVE-2013-6732 EPSS 0.00
IBM Cognos Business Intelligence - XSS
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
CWE-79 Feb 22, 2014
CVE-2014-1879 EPSS 0.00
phpMyAdmin <4.1.7 - XSS
Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.
CWE-79 Feb 20, 2014
CVE-2014-0081 EPSS 0.01
Ruby on Rails <4.1.0.beta2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
CWE-79 Feb 20, 2014
CVE-2014-0735 EPSS 0.00
Cisco Unified Communications Manager < 10.0\(1\) - XSS
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum46470.
CWE-79 Feb 20, 2014
CVE-2014-2018 EPSS 0.01
Mozilla Thunderbird <17.0.8 & SeaMonkey <2.20 - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in a (1) OBJECT or (2) EMBED element, a related issue to CVE-2013-6674.
CWE-79 Feb 17, 2014
CVE-2013-6674 1 PoC Analysis EPSS 0.48
Mozilla Seamonkey < 2.20 - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.
CWE-79 Feb 17, 2014
CVE-2013-1070 EPSS 0.00
Ubuntu MaaS 1.2-1.4 - XSS
Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.
CWE-79 Feb 17, 2014
CVE-2013-7326 EPSS 0.00
vTiger CRM 5.4.0 - XSS
Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) return_url parameter to modules\com_vtiger_workflow\savetemplate.php, or unspecified vectors to (2) deletetask.php, (3) edittask.php, (4) savetask.php, or (5) saveworkflow.php.
CWE-79 Feb 14, 2014
CVE-2013-7032 EPSS 0.00
Livezilla < 5.1.2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name of an uploaded file or (2) customer name in a resource created from an uploaded file, a different vulnerability than CVE-2013-7003.
CWE-79 Feb 14, 2014