Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,490 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,201 vendors 42,812 researchers
42,624 results Clear all
CVE-2012-6585 1 PoC Analysis EPSS 0.01
Myrephp Myre Realty Manager - XSS
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.
CWE-79 Aug 25, 2013
CVE-2013-5587 EPSS 0.00
RT <4.0.13 - XSS
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
CWE-79 Aug 23, 2013
CVE-2013-3372 EPSS 0.00
Request Tracker <3.8.17, <4.0.13 - XSS
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
CWE-79 Aug 23, 2013
CVE-2013-3371 EPSS 0.00
Request Tracker <4.0.13 - XSS
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment.
CWE-79 Aug 23, 2013
CVE-2013-5570 EPSS 0.00
TYPO3 <1.1.14 - XSS
Cross-site scripting (XSS) vulnerability in the Javascript and CSS Optimizer extension before 1.1.14 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 23, 2013
CVE-2012-6583 EPSS 0.00
Imagemenu - XSS
Cross-site scripting (XSS) vulnerability in the Imagemenu module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer imagemenu" permission to inject arbitrary web script or HTML via an image file name.
CWE-79 Aug 23, 2013
CVE-2013-2299 1 PoC Analysis EPSS 0.01
Advantech Webaccess < 7.0 - XSS
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 22, 2013
CVE-2013-4005 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
CWE-79 Aug 21, 2013
CVE-2013-4004 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 21, 2013
CVE-2013-2967 EPSS 0.00
IBM WebSphere Application Server <8.5.5.0 - XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 21, 2013
CVE-2013-0597 EPSS 0.00
IBM WebSphere Application Server <8.5.5.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 21, 2013
CVE-2013-4229 EPSS 0.00
Monster Menus - XSS
Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page settings.
CWE-79 Aug 21, 2013
CVE-2013-5323 EPSS 0.00
TYPO3 static_info_tables <2.3.1 - XSS
Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 20, 2013
CVE-2012-6582 EPSS 0.01
Spambot - XSS
Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the watchdog.
CWE-79 Aug 20, 2013
CVE-2013-5320 EPSS 0.00
mojoPortal <2.3.9.8 - XSS
Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter.
CWE-79 Aug 20, 2013
CVE-2013-5319 EPSS 0.01
Atlassian JIRA <6.0.5 - XSS
Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUser!default.jspa.
CWE-79 Aug 20, 2013
CVE-2013-5317 1 PoC Analysis EPSS 0.00
RiteCMS 1.0.0 - XSS
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cms/index.php.
CWE-79 Aug 20, 2013
CVE-2013-4653 EPSS 0.01
Alcatel-Lucent Omnitouch - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.
CWE-79 Aug 20, 2013
CVE-2013-5315 EPSS 0.01
Scald module <7.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174.
CWE-79 Aug 19, 2013
CVE-2013-4174 EPSS 0.01
OWS Scald - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flash_width, or (3) flash_height in the scald_flash_scald_prerender function in providers/scald_flash/scald_flash.module; or the (4) caption in the scald_image_scald_prerender function in providers/scald_image/scald_image.module.
CWE-79 Aug 19, 2013