Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
42,625 results Clear all
CVE-2013-7129 EPSS 0.00
ThemeBeans Bloogg <1.1 - XSS
Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the jQuery parameter to assets/js/jplayer.swf.
CWE-79 Dec 17, 2013
CVE-2013-6882 1 PoC Analysis EPSS 0.11
Cru-inc Ditto Forensic Fieldstation Firmware < 2013oct15a - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.
CWE-79 Dec 17, 2013
CVE-2013-6733 EPSS 0.00
IBM Sametime - XSS
Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 17, 2013
CVE-2013-6721 EPSS 0.00
IBM Websphere Service Registry And Repository - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.
CWE-79 Dec 17, 2013
CVE-2013-6327 EPSS 0.00
IBM Sterling Connect Enterprise HTTP Option - XSS
Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.
CWE-79 Dec 17, 2013
CVE-2013-6191 EPSS 0.01
HP Operations Orchestration < 7.5 - XSS
Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 17, 2013
CVE-2013-6963 EPSS 0.00
Cisco Webex Training Center - XSS
Cross-site scripting (XSS) vulnerability in the registration component in Cisco WebEx Training Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207.
CWE-79 Dec 14, 2013
CVE-2013-6962 EPSS 0.00
Cisco Webex Meeting Center - XSS
Cross-site scripting (XSS) vulnerability in the mobile-browser subsystem in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36228.
CWE-79 Dec 14, 2013
CVE-2013-6961 EPSS 0.00
Cisco Webex Meeting Center - XSS
Cross-site scripting (XSS) vulnerability in the Collaboration Partner Access Console (CPAC) in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36237.
CWE-79 Dec 14, 2013
CVE-2013-6960 EPSS 0.00
Cisco Webex Meeting Center - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248.
CWE-79 Dec 14, 2013
CVE-2013-6711 EPSS 0.00
Cisco Webex Sales Center - XSS
Cross-site scripting (XSS) vulnerability in the product-creation administrative page in Cisco WebEx Sales Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul25540.
CWE-79 Dec 14, 2013
CVE-2013-5438 EPSS 0.00
IBM Flex System Manager <1.4 - XSS
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 14, 2013
CVE-2013-4845 EPSS 0.01
HP Officejet Pro 8500 - XSS
Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka A909) All-in-One printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 14, 2013
CVE-2013-6957 EPSS 0.00
Juniper Idp250 - XSS
Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web server.
CWE-79 Dec 13, 2013
CVE-2013-6956 EPSS 0.00
Juniper Ive OS - XSS
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 13, 2013
CVE-2013-6005 EPSS 0.00
Cybozu Dezie < 8.0.7 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button.
CWE-79 Dec 13, 2013
CVE-2013-5612 EPSS 0.01
Mozilla Firefox <26.0 & SeaMonkey <2.23 - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
CWE-79 Dec 11, 2013
CVE-2013-5072 EPSS 0.07
Microsoft Exchange <2013 CU3 - XSS
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."
CWE-79 Dec 11, 2013
CVE-2013-5042 EPSS 0.10
Microsoft ASP.NET SignalR <1.1.4, 2.0.x <2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."
CWE-79 Dec 11, 2013
CVE-2013-5404 EPSS 0.00
IBM RQM <4.0.5 - XSS
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.
CWE-79 Dec 10, 2013