Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,480 CVEs tracked 53,336 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,227 vendors 42,821 researchers
42,625 results Clear all
CVE-2014-0812 EPSS 0.00
Kent-web Joyful Note < 2.8 - XSS
Cross-site scripting (XSS) vulnerability in KENT-WEB Joyful Note 2.8 and earlier, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 01, 2014
CVE-2013-6235 EPSS 0.00
Steve Souza Java Application Monitor < 2.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.
CWE-79 Jan 31, 2014
CVE-2013-4383 EPSS 0.00
Dennis Bruecke Jquery Countdown - XSS
Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 31, 2014
CVE-2013-7303 EPSS 0.00
SPIP <3.0.13 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.
CWE-79 Jan 30, 2014
CVE-2014-1837 EPSS 0.00
Joomla! com_komento <1.7.4 - XSS
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."
CWE-79 Jan 30, 2014
CVE-2014-1612 EPSS 0.01
Media5 Mediatrix 4402 <1.1.13.186 - XSS
Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
CWE-79 Jan 30, 2014
CVE-2014-1611 EPSS 0.00
Drupal 7.x-1.2,7.x-1.3 - XSS
Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.
CWE-79 Jan 30, 2014
CVE-2014-0793 1 PoC Analysis EPSS 0.01
Stackideas Komento < 1.7.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI.
CWE-79 Jan 30, 2014
CVE-2013-3090 EPSS 0.00
Belkin N300 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.
CWE-79 Jan 30, 2014
CVE-2013-3087 EPSS 0.00
Belkin N900 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.
CWE-79 Jan 30, 2014
CVE-2013-3084 EPSS 0.00
Belkin Model F5D8236-4 v2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model F5D8236-4 v2 router allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 30, 2014
CVE-2013-0177 1 PoC Analysis EPSS 0.02
Apache Ofbiz - XSS
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.
CWE-79 Jan 30, 2014
CVE-2014-0836 EPSS 0.00
IBM Qradar Security Information And Event Manager < 7.2.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jan 30, 2014
CVE-2013-7318 EPSS 0.00
AlgoSec Firewall Analyzer 6.4 - XSS
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Jan 29, 2014
CVE-2013-5092 1 PoC Analysis EPSS 0.04
AlgoSec Firewall Analyzer 6.1-b86 - XSS
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Jan 29, 2014
CVE-2013-5005 EPSS 0.00
Tripwire Enterprise <8.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.
CWE-79 Jan 29, 2014
CVE-2013-4888 1 PoC Analysis EPSS 0.00
Digital Signage Xibo 1.4.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.
CWE-79 Jan 29, 2014
CVE-2014-0681 EPSS 0.01
Cisco Identity Services Engine Software < 1.2 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.
CWE-79 Jan 29, 2014
CVE-2014-0680 EPSS 0.01
Cisco Identity Services Engine - XSS
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.
CWE-79 Jan 29, 2014
CVE-2013-5094 1 PoC Analysis EPSS 0.06
McAfee VM 7.5 - XSS
Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.
CWE-79 Jan 28, 2014