Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
42,578 results Clear all
CVE-2012-6564 EPSS 0.00
Vanderbilt Redcap < 4.14.4 - XSS
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 17, 2013
CVE-2013-2309 EPSS 0.00
Tejimaya Openpne - XSS
Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."
CWE-79 Jun 17, 2013
CVE-2013-2337 EPSS 0.01
HP Service Manager - XSS
Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 14, 2013
CVE-2013-3645 EPSS 0.00
Orchard < 1.6 - XSS
Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 14, 2013
CVE-2013-3375 EPSS 0.00
Cisco Prime Central - XSS
Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798.
CWE-79 Jun 14, 2013
CVE-2013-3640 EPSS 0.00
Filemaker Pro < 11.0.4.0 - XSS
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 10, 2013
CVE-2013-1012 EPSS 0.00
Apple Safari <6.0.5 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
CWE-79 Jun 05, 2013
CVE-2013-0464 EPSS 0.00
IBM Eclipse Help System <3.4.3, <3.6.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jun 03, 2013
CVE-2013-0549 EPSS 0.00
IBM WebSphere Portal <8.0.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jun 03, 2013
CVE-2013-3261 EPSS 0.00
WordPress GRAND FlAGallery <2.72 - XSS
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
CWE-79 Jun 01, 2013
CVE-2013-1247 EPSS 0.00
Cisco Prime Infrastructure - XSS
Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remote attackers to inject arbitrary web script or HTML via an SSID that is not properly handled during display of the XML windowing table, aka Bug ID CSCuf04356.
CWE-79 May 31, 2013
CVE-2013-3720 EPSS 0.00
Feedweb < 1.8.8 - XSS
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.
CWE-79 May 31, 2013
CVE-2013-3719 EPSS 0.00
Algisinfo Aicontactsafe < 2.0.19 - XSS
Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 31, 2013
CVE-2013-2314 EPSS 0.00
Lockon Ec-cube - XSS
Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen.
CWE-79 May 29, 2013
CVE-2013-2312 EPSS 0.00
Lockon Ec-cube - XSS
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 May 29, 2013
CVE-2013-0499 EPSS 0.00
IBM WebSphere DataPower SOA - XSS
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.
CWE-79 May 28, 2013
CVE-2013-0576 EPSS 0.00
IBM Tivoli Monitoring <6.2.3 - XSS
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 28, 2013
CVE-2013-2957 EPSS 0.00
IBM InfoSphere Optim Data Growth - XSS
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 May 27, 2013
CVE-2013-2955 EPSS 0.00
IBM InfoSphere Optim Data Growth - XSS
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, related to a stored XSS issue.
CWE-79 May 27, 2013
CVE-2012-6561 EPSS 0.00
Elgg < 1.8.4 - XSS
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.
CWE-79 May 23, 2013