Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
42,625 results Clear all
CVE-2012-3047 EPSS 0.00
Cisco Scientific Atlanta D20-D30 - XSS
Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 10, 2013
CVE-2013-6224 EPSS 0.00
Livezilla < 5.1.0.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a name in the call administrator feature, (2) unspecified vectors to the admins visitor information panel, or (3) a text message in a chat session, which is saved in the archive section.
CWE-79 Dec 10, 2013
CVE-2013-6039 EPSS 0.01
Nagiosql - XSS
Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/hostdependencies.php, (2) admin/hosts.php, or other unspecified pages that allow search input, related to the search functionality in functions/content_class.php.
CWE-79 Dec 09, 2013
CVE-2013-3929 EPSS 0.00
Cmsmadesimple Cms Made Simple - XSS
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.
CWE-79 Dec 09, 2013
CVE-2013-7025 1 PoC Analysis EPSS 0.03
Sonicwall Analyzer - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2) value_1 parameter to createNewThreshold.jsp.
CWE-79 Dec 09, 2013
CVE-2013-4171 EPSS 0.02
Apache Roller < 5.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
CWE-79 Dec 07, 2013
CVE-2013-6416 EPSS 0.00
Rails < 4.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
CWE-79 Dec 07, 2013
CVE-2013-6415 EPSS 0.02
Rails < 3.2.15 - XSS
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
CWE-79 Dec 07, 2013
CVE-2013-4492 1 Writeup EPSS 0.00
I18n < 0.6.5 - XSS
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
CWE-79 Dec 07, 2013
CVE-2013-4491 EPSS 0.01
Rails < 4.0.1 - XSS
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
CWE-79 Dec 07, 2013
CVE-2013-6804 EPSS 0.00
Jamroom Search Module < 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to search/results/all/1/4.
CWE-79 Dec 05, 2013
CVE-2013-6395 EPSS 0.01
Ganglia-web - XSS
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.
CWE-79 Dec 05, 2013
CVE-2013-6267 EPSS 0.01
Claroline < 1.11.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit parameter to (2) adminregisteruser.php or (3) admin_user_course_settings.php in admin/, (4) module_id parameter to admin/module/module.php, or (5) offset parameter to admin/right/profile_list.php.
CWE-79 Dec 05, 2013
CVE-2013-5108 EPSS 0.01
RockMongo <1.1.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db parameter on the login page or (2) username parameter in a login.index action to index.php and other unspecified parameters.
CWE-79 Dec 05, 2013
CVE-2013-6916 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013
CVE-2013-6915 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013
CVE-2013-6914 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013
CVE-2013-6913 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013
CVE-2013-6912 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013
CVE-2013-6911 EPSS 0.00
Cybozu Garoon < 3.7 - XSS
Cross-site scripting (XSS) vulnerability in the bulletin-board component in Cybozu Garoon before 3.7.2, when Internet Explorer or Firefox is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2013