Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
42,564 results Clear all
CVE-2012-3316 EPSS 0.00
IBM Maximo Asset Management - XSS
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 20, 2013
CVE-2012-4352 EPSS 0.00
Stone-ware Webnetwork - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork 6.1 before SP1 allow remote attackers to inject arbitrary web script or HTML via the blogName parameter to (1) community/blog.jsp or (2) community/blogSearch.jsp, the (3) calendarType or (4) monthNumber parameter to community/calendar.jsp, or the (5) flag parameter to swDashboard/ajax/setAppFlag.jsp.
CWE-79 Feb 18, 2013
CVE-2013-1123 EPSS 0.01
Cisco Unified MeetingPlace 7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706.
CWE-79 Feb 15, 2013
CVE-2013-0703 EPSS 0.00
imgboard.com <1.22R6.1, 20xx <2010 - XSS
Cross-site scripting (XSS) vulnerability in imgboard.com imgboard before 1.22R6.1 u and 20xx before 2010u allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 15, 2013
CVE-2013-0702 EPSS 0.00
Cybozu Garoon <3.5.3 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 3.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2013
CVE-2013-1114 1 PoC Analysis EPSS 0.13
Cisco Unity Express <8.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527.
CWE-79 Feb 13, 2013
CVE-2011-5265 1 PoC Analysis NUCLEI EPSS 0.06
Featurific FOR Wordpress Featurific-for-wordpress - XSS
Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.
CWE-79 Feb 12, 2013
CVE-2011-5264 EPSS 0.01
Marcel Brinkkemper Lazyest-backup < 0.2.1 - XSS
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.
CWE-79 Feb 12, 2013
CVE-2011-5263 EPSS 0.00
SAP Netweaver < 7.30 - XSS
Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.
CWE-79 Feb 12, 2013
CVE-2011-5261 1 PoC Analysis EPSS 0.02
Axis M10 Series Network Cameras Firmware < 5.21 - XSS
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.
CWE-79 Feb 12, 2013
CVE-2011-5260 EPSS 0.00
SAP Netweaver - XSS
Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Feb 12, 2013
CVE-2011-5258 2 PoCs Analysis EPSS 0.07
Orangehrm < 2.6.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.
CWE-79 Feb 12, 2013
CVE-2011-5257 1 PoC Analysis EPSS 0.04
Appthemes Classipress < 3.1.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parameter related to the Facebook widget.
CWE-79 Feb 12, 2013
CVE-2011-5256 EPSS 0.00
Limesurvey < 1.91\+ - XSS
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
CWE-79 Feb 12, 2013
CVE-2013-1464 1 PoC Analysis EPSS 0.04
Doryphores Audio Player < 2.0.4.5 - XSS
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.
CWE-79 Feb 07, 2013
CVE-2013-1463 1 PoC Analysis EPSS 0.07
Wp-table Reloaded < 1.9.4 - XSS
Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be the same vulnerability as CVE-2013-1808. If so, it is likely that CVE-2013-1463 will be REJECTed.
CWE-79 Feb 07, 2013
CVE-2012-5186 EPSS 0.00
FLUGELz netmania myu-s/PHP WeblogSystem - XSS
Cross-site scripting (XSS) vulnerability in FLUGELz netmania myu-s and PHP WeblogSystem allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 06, 2013
CVE-2012-3279 EPSS 0.01
HP NNMi <9.20 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 06, 2013
CVE-2012-1064 EPSS 0.00
EMC RSA Archer <5.2SP1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 06, 2013
CVE-2013-1471 1 PoC Analysis EPSS 0.05
Fortinet Fortimail < 4.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.
CWE-79 Feb 04, 2013