Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
42,625 results Clear all
CVE-2013-3394 EPSS 0.00
Cisco Prime Network Registrar < 8.1 - XSS
Cross-site scripting (XSS) vulnerability in the web interface in Cisco Prime Network Registrar 8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted field, aka Bug ID CSCuh41429.
CWE-79 Nov 27, 2013
CVE-2013-4525 EPSS 0.00
Moodle <2.5.3 - XSS
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.
CWE-79 Nov 26, 2013
CVE-2013-4523 EPSS 0.00
Moodle <2.2.11, <2.3.10, <2.4.7, <2.5.3 - XSS
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.
CWE-79 Nov 26, 2013
CVE-2013-6870 EPSS 0.00
Splunk < 5.0.5 - XSS
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2013
CVE-2013-6374 EPSS 0.00
Jenkins-ci Build Failure Analyzer < 1.5.0 - XSS
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2013
CVE-2013-4573 EPSS 0.00
MediaWiki <1.19.9, 1.20.8, 1.21.3 - XSS
Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to inject arbitrary web script or HTML via the "to" parameter to index.php.
CWE-79 Nov 25, 2013
CVE-2012-6608 1 PoC Analysis EPSS 0.01
Elastix - XSS
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter.
CWE-79 Nov 25, 2013
CVE-2013-6858 EPSS 0.00
Openstack Horizon < 2013.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
CWE-79 Nov 23, 2013
CVE-2013-6342 EPSS 0.00
Tweet-blender < 4.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.
CWE-79 Nov 22, 2013
CVE-2013-3288 EPSS 0.00
EMC RSA DPM <3.2.4.2, <3.5.1 - XSS
Cross-site scripting (XSS) vulnerability on the EMC RSA Data Protection Manager (DPM) appliance 3.2.x before 3.2.4.2 and 3.5.x before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Nov 22, 2013
CVE-2013-6175 EPSS 0.00
EMC Document Sciences Xpression - XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to inject arbitrary web script or HTML via unspecified input to a (1) xAdmin or (2) xDashboard form.
CWE-79 Nov 21, 2013
CVE-2013-5996 EPSS 0.00
Lockon Ec-cube - XSS
Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through 2.13.0 allow remote attackers to inject arbitrary web script or HTML via crafted values.
CWE-79 Nov 21, 2013
CVE-2013-5992 EPSS 0.00
Lockon Ec-cube - XSS
Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to inject arbitrary web script or HTML by leveraging incorrect handling of error-message output.
CWE-79 Nov 21, 2013
CVE-2013-6819 EPSS 0.00
SAP Netweaver - XSS
Cross-site scripting (XSS) vulnerability in Performance Provider in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 20, 2013
CVE-2013-6816 EPSS 0.00
SAP Netweaver - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) JavaDumpService and (2) DataCollector servlets in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 20, 2013
CVE-2013-6074 EPSS 0.00
Open-xchange Appsuite - XSS
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote attackers to inject arbitrary web script or HTML via an attached SVG file.
CWE-79 Nov 20, 2013
CVE-2013-5966 1 Writeup EPSS 0.00
Zkoss ZK Framework < 5.0.12 - XSS
Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 20, 2013
CVE-2013-5215 EPSS 0.00
FOSCAM Wireless IP Cameras - XSS
Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID.
CWE-79 Nov 20, 2013
CVE-2013-4507 EPSS 0.00
Collectiveaccess Pawtucket < 1.3 - XSS
Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 20, 2013
CVE-2013-6042 1 PoC Analysis EPSS 0.01
Softaculous Webuzo < 2.1.3 - XSS
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
CWE-79 Nov 19, 2013