Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
42,578 results Clear all
CVE-2013-0542 EPSS 0.00
IBM WebSphere Application Server <8.5.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.
CWE-79 Apr 24, 2013
CVE-2013-0503 EPSS 0.00
IBM Lotus Connections <4.0 CR3 - XSS
Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 23, 2013
CVE-2012-5949 EPSS 0.00
IBM Tririga Application Platform - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.
CWE-79 Apr 23, 2013
CVE-2012-5948 EPSS 0.00
IBM Tririga Application Platform - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.
CWE-79 Apr 23, 2013
CVE-2012-6092 EPSS 0.03
Apache Activemq < 5.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
CWE-79 Apr 21, 2013
CVE-2013-1086 EPSS 0.01
Novell GroupWise <8.0.3 HP3, 2012 <SP2 - XSS
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.
CWE-79 Apr 19, 2013
CVE-2013-0129 EPSS 0.00
Pd-admin < 4.16 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message.
CWE-79 Apr 19, 2013
CVE-2013-1749 EPSS 0.00
Chatelao Php Address Book - XSS
Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field.
CWE-79 Apr 18, 2013
CVE-2013-1937 6.1 MEDIUM 1 PoC Analysis EPSS 0.08
Phpmyadmin < 3.5.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable.
CWE-79 Apr 16, 2013
CVE-2013-2766 EPSS 0.00
Splunk <4.3.5 - XSS
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.3.0 through 4.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 10, 2013
CVE-2013-1289 EXPLOITED EPSS 0.45
Microsoft SharePoint <2010 SP1 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
CWE-79 Apr 09, 2013
CVE-2013-0134 EPSS 0.01
Airdroid - XSS
Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed phone.
CWE-79 Apr 09, 2013
CVE-2013-0125 1 PoC Analysis EPSS 0.02
C2enterprise C2 Webresource - XSS
Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.
CWE-79 Apr 04, 2013
CVE-2013-0793 EPSS 0.01
Mozilla Firefox <20 - XSS
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.
CWE-79 Apr 03, 2013
CVE-2012-1038 1 PoC Analysis EPSS 0.01
Juniper Networks MSS <7.6.3-7.7.1-7.5.3-7.4-7.3 - XSS
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.
CWE-79 Apr 03, 2013
CVE-2013-1823 EPSS 0.00
Redhat Subscription Asset Manager < 1.2.0 - XSS
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
CWE-79 Apr 02, 2013
CVE-2013-1808 1 Writeup EPSS 0.02
Zeroclipboard < 1.0.7 - XSS
Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.
CWE-79 Apr 02, 2013
CVE-2012-6550 1 PoC Analysis EPSS 0.04
Zeroclipboard < 1.0.7 - XSS
Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.
CWE-79 Apr 02, 2013
CVE-2013-1171 EPSS 0.00
Cisco CG-NMS - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the element-list implementation in Cisco Connected Grid Network Management System (CG-NMS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCue14517, CSCue38914, CSCue38884, CSCue38882, CSCue38881, CSCue38872, CSCue38868, CSCue38866, CSCue38853, and CSCue14540.
CWE-79 Apr 01, 2013
CVE-2013-0502 EPSS 0.00
IBM InfoSphere Information Server <9.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
CWE-79 Apr 01, 2013