Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,490 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,201 vendors 42,812 researchers
42,624 results Clear all
CVE-2013-5118 1 PoC Analysis EPSS 0.00
Good for Enterprise <2.2.4.1659 - XSS
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.
CWE-79 Sep 25, 2013
CVE-2013-5911 EPSS 0.00
Tenable Securitycenter - XSS
Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Sep 24, 2013
CVE-2013-3616 EPSS 0.01
Knowledgeview Editorial And Management Application - XSS
Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.
CWE-79 Sep 24, 2013
CVE-2013-3589 EPSS 0.01
Dell Idrac6 Firmware < 1.95 - XSS
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
CWE-79 Sep 24, 2013
CVE-2013-5930 EPSS 0.00
Real-estate-php-script Real Estate Php Script - XSS
Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter.
CWE-79 Sep 23, 2013
CVE-2013-5918 EPSS 0.00
Platinum Seo Plugin < 1.3.7 - XSS
Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Sep 23, 2013
CVE-2013-4814 EPSS 0.01
HP XP P9000 - XSS
Cross-site scripting (XSS) vulnerability in HP XP P9000 Command View Advanced Edition Suite Software 7.x before 7.5.0-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 23, 2013
CVE-2013-4815 EPSS 0.00
HP ArcSight ESM <5.5 - XSS
Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2013
CVE-2013-4052 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2013
CVE-2013-0596 EPSS 0.00
IBM WAS 6.1 - XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2013
CVE-2013-5501 EPSS 0.00
Cisco MediaSense - XSS
Cross-site scripting (XSS) vulnerability in the oraservice page in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj23328.
CWE-79 Sep 20, 2013
CVE-2013-5500 EPSS 0.00
Cisco MediaSense - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338.
CWE-79 Sep 20, 2013
CVE-2013-5151 EPSS 0.00
Apple iOS <7 - XSS
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
CWE-79 Sep 19, 2013
CVE-2013-5131 EPSS 0.00
Apple iOS <7 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Sep 19, 2013
CVE-2013-5129 EPSS 0.00
Apple iOS <7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CWE-79 Sep 19, 2013
CVE-2013-1034 EPSS 0.00
Apple Mac OS X Server <2.2.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 19, 2013
CVE-2013-1727 1 PoC Analysis EPSS 0.02
Mozilla Firefox < 23.0.1 - XSS
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
CWE-79 Sep 18, 2013
CVE-2013-5711 EPSS 0.00
Slickremix Design Approval System Plugin < 3.6 - XSS
Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin before 3.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
CWE-79 Sep 17, 2013
CVE-2013-4181 EPSS 0.00
Redhat Enterprise Virtualization - XSS
Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 16, 2013
CVE-2013-4048 EPSS 0.00
IBM Spss Analytical Decision Management - XSS
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.
CWE-79 Sep 16, 2013