Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
42,564 results Clear all
CVE-2012-6506 1 PoC Analysis EPSS 0.05
Zingiri Web Shop - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.
CWE-79 Jan 24, 2013
CVE-2012-6505 1 PoC Analysis EPSS 0.07
Shawn Bradley Php Volunteer Management - XSS
Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Jan 24, 2013
CVE-2012-2099 2 PoCs Analysis EPSS 0.27
Wikidforum - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search.
CWE-79 Jan 24, 2013
CVE-2011-4618 1 PoC Analysis NUCLEI EPSS 0.05
Simplerealtytheme Advanced Text Widget Plugin < 2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Jan 24, 2013
CVE-2012-5184 EPSS 0.00
Olive Toast Documents Pro File Viewer <1.11.1 - XSS
Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 19, 2013
CVE-2012-6360 EPSS 0.00
IBM Intelligent Operations Center - XSS
Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject arbitrary web script or HTML via event data fields.
CWE-79 Jan 18, 2013
CVE-2012-5531 EPSS 0.00
JBoss Enterprise Portal Platform 5.2.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 18, 2013
CVE-2012-6397 EPSS 0.00
Cisco Quad - XSS
Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub61977.
CWE-79 Jan 17, 2013
CVE-2013-0010 EPSS 0.25
Microsoft System Center Operations Manager - XSS
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
CWE-79 Jan 09, 2013
CVE-2013-0009 EPSS 0.25
Microsoft System Center Operations Manager - XSS
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
CWE-79 Jan 09, 2013
CVE-2012-4543 EPSS 0.00
Red Hat Certificate System <8.1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.
CWE-79 Jan 04, 2013
CVE-2012-6082 EPSS 0.00
Moinmoin < 1.9.6 - XSS
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
CWE-79 Jan 03, 2013
CVE-2012-5666 2 Writeups EPSS 0.00
ownCloud <4.0.10, <4.5.5 - XSS
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.
CWE-79 Jan 03, 2013
CVE-2012-6464 EPSS 0.00
Opera Browser < 12.10 - XSS
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.
CWE-79 Jan 02, 2013
CVE-2012-6463 EPSS 0.00
Opera Browser < 12.10 - XSS
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs.
CWE-79 Jan 02, 2013
CVE-2012-4970 EPSS 0.00
Polycom HDX Video End Points <2.7.1.1_J-3.0.5 - XSS
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 01, 2013
CVE-2012-6453 EPSS 0.00
Mediawiki Rssreader < 0.2.5 - XSS
Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a crafted feed.
CWE-79 Dec 31, 2012
CVE-2012-6339 EPSS 0.00
Cerberusftp FTP Server < 5.0.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and might allow (2) remote authenticated administrators to inject arbitrary web script or HTML via a Messages field to the servermanager program.
CWE-79 Dec 31, 2012
CVE-2012-6369 EPSS 0.00
1password - XSS
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action.
CWE-79 Dec 28, 2012
CVE-2012-4932 1 PoC Analysis EPSS 0.00
SimpleInvoices <stable-2012-1-CIS3000 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the Customer Name field in an Add Customer action; the (4) Street address, (5) Street address 2, (6) City, (7) Zip code, (8) State, (9) Country, (10) Mobile Phone, (11) Phone, (12) Fax, (13) Email, (14) PayPal business name, (15) PayPal notify url, (16) PayPal return url, (17) Eway customer ID, (18) Custom field 1, (19) Custom field 2, (20) Custom field 3, or (21) Custom field 4 field in an Add Biller action; (22) the Customer field in an Add Invoice action; the (23) Invoice or (24) Notes field in a Process Payment action; (25) the Payment type description field in a Payment Types action; (26) the Description field in an Invoice Preferences action; (27) the Description field in a Manage Products action; or (28) the Description field in a Tax Rates action.
CWE-79 Dec 28, 2012