Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
42,578 results Clear all
CVE-2013-0319 EPSS 0.00
Yandex.metrics Yandex Metrics - XSS
Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.
CWE-79 Mar 27, 2013
CVE-2013-0317 EPSS 0.00
JOE Haskins OG Manager Change - XSS
Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.
CWE-79 Mar 27, 2013
CVE-2013-0259 EPSS 0.00
Boxes - XSS
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.
CWE-79 Mar 27, 2013
CVE-2013-0181 EPSS 0.01
Thomas Seidl Search API - XSS
Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.
CWE-79 Mar 27, 2013
CVE-2013-0488 EPSS 0.00
IBM Domino <8.5 - XSS
Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 27, 2013
CVE-2013-0525 EPSS 0.00
IBM iNotes <8.5.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.
CWE-79 Mar 26, 2013
CVE-2012-5943 EPSS 0.00
IBM Lotus Inotes - XSS
Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.
CWE-79 Mar 26, 2013
CVE-2013-1833 EPSS 0.00
Moodle - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
CWE-79 Mar 25, 2013
CVE-2013-2501 1 PoC Analysis EPSS 0.06
Terillion Reviews <1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
CWE-79 Mar 22, 2013
CVE-2013-1844 EPSS 0.00
Matomo < 1.10.1 - XSS
Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 21, 2013
CVE-2013-0124 EPSS 0.01
Askiaweb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to inject arbitrary web script or HTML via the (1) Number or (2) UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.
CWE-79 Mar 21, 2013
CVE-2013-0453 EPSS 0.00
IBM Tivoli Endpoint Manager < 8.2 - XSS
Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli Endpoint Manager (TEM) before 8.2.1372 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 21, 2013
CVE-2012-5757 EPSS 0.00
IBM Rational Clearquest - XSS
Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 21, 2013
CVE-2013-0672 EPSS 0.00
Siemens WinCC (TIA Portal) 11 - XSS
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.
CWE-79 Mar 21, 2013
CVE-2013-0668 EPSS 0.00
Siemens WinCC (TIA Portal) 11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 21, 2013
CVE-2013-0667 EPSS 0.00
Siemens WinCC (TIA Portal) 11 - XSS
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 21, 2013
CVE-2013-1857 EPSS 0.01
Redhat Enterprise Linux < 2.3.17 - XSS
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a &#x3a; sequence.
CWE-79 Mar 19, 2013
CVE-2013-1855 EPSS 0.01
Rails < 2.3.17 - XSS
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
CWE-79 Mar 19, 2013
CVE-2013-0506 EPSS 0.00
IBM Sterling Order Management <9.2.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2013
CVE-2013-0227 EPSS 0.00
Mathijs Koenraadt Search API Sorts - XSS
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.
CWE-79 Mar 19, 2013