Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
42,578 results Clear all
CVE-2013-3396 EPSS 0.00
Cisco Content Security Management Appliance - XSS
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.
CWE-79 Jun 26, 2013
CVE-2013-2177 EPSS 0.00
Kristof DE Jaeger Display Suite - XSS
Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.
CWE-79 Jun 25, 2013
CVE-2013-1971 EPSS 0.00
Jordan DE Laune Mp3 Player < 6.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.
CWE-79 Jun 25, 2013
CVE-2012-6573 EPSS 0.01
Alejandro Garza Apachesolr Autocomplete - XSS
Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.
CWE-79 Jun 25, 2013
CVE-2013-2129 EPSS 0.00
Nathan Haug Webform < 6.x-3.18 - XSS
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label.
CWE-79 Jun 24, 2013
CVE-2013-2036 EPSS 0.00
Yoran Brault Filebrowser - XSS
Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."
CWE-79 Jun 24, 2013
CVE-2013-1972 EPSS 0.00
Alexey Sukhotin Elfinder - XSS
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.
CWE-79 Jun 24, 2013
CVE-2013-1906 EPSS 0.00
Wolfgang Ziegler Rules - XSS
Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "administer rules" permission to inject arbitrary web script or HTML via a rule tag.
CWE-79 Jun 24, 2013
CVE-2012-6572 EPSS 0.00
Kong Inf08 - XSS
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name.
CWE-79 Jun 21, 2013
CVE-2013-0548 EPSS 0.00
IBM Tivoli Monitoring <6.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 21, 2013
CVE-2013-1905 EPSS 0.00
Catalin Florian Radut Zeropoint - XSS
Cross-site scripting (XSS) vulnerability in the Zero Point theme 7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 20, 2013
CVE-2013-1393 EPSS 0.00
Curvycorners - XSS
Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 20, 2013
CVE-2013-2969 EPSS 0.00
IBM Sterling Control Center <5.2.0.9-5.4.0.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.
CWE-79 Jun 19, 2013
CVE-2013-4612 EPSS 0.00
REDCap <5.1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.
CWE-79 Jun 17, 2013
CVE-2013-4608 EPSS 0.00
REDCap <5.0.6 - XSS
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.
CWE-79 Jun 17, 2013
CVE-2013-1097 EPSS 0.01
Novell ZENworks Configuration Management <11.2.3a - XSS
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.
CWE-79 Jun 17, 2013
CVE-2013-1095 EPSS 0.01
Novell ZENworks Configuration Management <11.2.3a - XSS
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError event.
CWE-79 Jun 17, 2013
CVE-2013-1094 EPSS 0.01
Novell ZENworks <11.2.3a - XSS
Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.
CWE-79 Jun 17, 2013
CVE-2012-6566 EPSS 0.00
Vanderbilt Redcap < 4.14.1 - XSS
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 17, 2013
CVE-2012-6565 EPSS 0.00
Vanderbilt Redcap < 4.14.2 - XSS
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.
CWE-79 Jun 17, 2013