Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
42,625 results Clear all
CVE-2011-5269 EPSS 0.00
Projectforge < 3.5.2 - XSS
Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a validation message.
CWE-79 Jan 02, 2014
CVE-2013-3572 6.1 MEDIUM EPSS 0.00
UI Unifi Controller < 2.3.6 - XSS
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.
CWE-79 Dec 31, 2013
CVE-2013-6459 EPSS 0.00
Mislav Marohnic Will Paginate < 3.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
CWE-79 Dec 31, 2013
CVE-2013-5573 1 PoC Analysis EPSS 0.03
Jenkins 1.523 - XSS
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.
CWE-79 Dec 31, 2013
CVE-2013-7241 EPSS 0.00
Zenphoto <1.4.5.4 - XSS
Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.
CWE-79 Dec 31, 2013
CVE-2013-7231 EPSS 0.00
ESRI ArcGIS for Server <10.3 - XSS
Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.
CWE-79 Dec 30, 2013
CVE-2013-5222 EPSS 0.00
ESRI ArcGIS for Server 10.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2013
CVE-2013-5218 1 PoC Analysis EPSS 0.01
HOT HOTBOX <2.1.11 - XSS
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.
CWE-79 Dec 30, 2013
CVE-2013-5210 EPSS 0.00
ADTRAN AOS <R10.8.1 - XSS
Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2013
CVE-2013-6198 EPSS 0.02
HP Service Manager - XSS
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 29, 2013
CVE-2013-5583 EPSS 0.00
Joomla! 3.1.5 - XSS
Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CWE-79 Dec 29, 2013
CVE-2013-2504 1 PoC Analysis EPSS 0.01
Matrix42 Service Store <5.33.946.0 - XSS
Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.
CWE-79 Dec 29, 2013
CVE-2013-6808 EPSS 0.00
Zendto < 4.11-12 - XSS
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.
CWE-79 Dec 28, 2013
CVE-2013-1096 EPSS 0.02
Novell IDM <4.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
CWE-79 Dec 28, 2013
CVE-2013-6388 EPSS 0.00
Drupal - XSS
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.
CWE-79 Dec 24, 2013
CVE-2013-6387 EPSS 0.00
Drupal - XSS
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
CWE-79 Dec 24, 2013
CVE-2013-4424 EPSS 0.00
Redhat Jboss Enterprise Portal Platform - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 23, 2013
CVE-2013-4414 EPSS 0.00
Redhat Enterprise Mrg - XSS
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
CWE-79 Dec 23, 2013
CVE-2013-6745 EPSS 0.00
IBM Security Access Manager For Enterprise Single Sign-on - XSS
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.
CWE-79 Dec 22, 2013
CVE-2013-6328 EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
CWE-79 Dec 22, 2013