Exploit Intelligence Platform

Updated 50m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
42,564 results Clear all
CVE-2012-4983 EPSS 0.00
Forescout CounterACT <7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch.
CWE-79 Dec 05, 2012
CVE-2012-5569 EPSS 0.00
Drupal Basic Webmail <6.x-1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
CWE-79 Dec 03, 2012
CVE-2012-5559 EPSS 0.00
Drupal ctools <6.x-1.10 - XSS
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.
CWE-79 Dec 03, 2012
CVE-2012-5553 EPSS 0.00
OM Maximenu <7.x-1.44 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with the "administer OM Maximenu" permission to inject arbitrary web script or HTML via the (1) Menu Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary names.
CWE-79 Dec 03, 2012
CVE-2012-5551 EPSS 0.00
MailChimp module <7.x-2.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests."
CWE-79 Dec 03, 2012
CVE-2012-5548 EPSS 0.00
Drupal Time Spent <7 - XSS
Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 03, 2012
CVE-2012-5545 EPSS 0.00
ShareThis module <7.x-2.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis module 7.x-2.x before 7.x-2.5 for Drupal allow remote authenticated users with the "administer sharethis" permission to inject arbitrary web script or HTML via unspecified vectors related to "JavaScript settings."
CWE-79 Dec 03, 2012
CVE-2012-5541 EPSS 0.00
Twitter Pull module <7.x-1.0-rc3 - XSS
Cross-site scripting (XSS) vulnerability in the Twitter Pull module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "data coming from Twitter."
CWE-79 Dec 03, 2012
CVE-2012-5540 EPSS 0.00
Hostip module <7.x-2.2,6.x-2.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Hostip module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers with control of hostip.info to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 03, 2012
CVE-2012-5538 EPSS 0.00
Drupal FileField Sources <7.x-1.6 - XSS
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
CWE-79 Dec 03, 2012
CVE-2012-4476 EPSS 0.00
David Alkire Drag & Drop Gallery - XSS
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 30, 2012
CVE-2012-4474 EPSS 0.00
Colorbox Node Dennis Blake - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Nov 30, 2012
CVE-2012-4469 EPSS 0.00
Simon Rycroft Hashcash - XSS
Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.
CWE-79 Nov 30, 2012
CVE-2012-4468 EPSS 0.00
Privatemsg - XSS
Cross-site scripting (XSS) vulnerability in the Privatemsg module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a user name in a private message.
CWE-79 Nov 30, 2012
CVE-2012-4611 EPSS 0.00
EMC RSA AAOP <7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 27, 2012
CVE-2012-6045 1 PoC Analysis EPSS 0.02
Ramui Forum - XSS
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
CWE-79 Nov 27, 2012
CVE-2010-5284 1 PoC Analysis EPSS 0.05
Collabtive 0.6.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.
CWE-79 Nov 26, 2012
CVE-2010-5282 EPSS 0.01
OpenText ECM 9.7.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html.
CWE-79 Nov 26, 2012
CVE-2012-6043 1 PoC Analysis EPSS 0.00
Php-fusion - XSS
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
CWE-79 Nov 26, 2012
CVE-2012-6040 1 PoC Analysis EPSS 0.01
Convergine File King Advanced File Management - XSS
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Nov 26, 2012