Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
42,560 results Clear all
CVE-2012-5908 1 PoC Analysis EPSS 0.05
Mybb - XSS
Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.
CWE-79 Nov 17, 2012
CVE-2012-5906 EPSS 0.01
Morequick Greenbrowser - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.
CWE-79 Nov 17, 2012
CVE-2012-5903 1 PoC Analysis EPSS 0.02
Simple Machines Smf - XSS
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.
CWE-79 Nov 17, 2012
CVE-2012-5902 EPSS 0.00
Dflabs Ptk - XSS
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.
CWE-79 Nov 17, 2012
CVE-2012-5899 1 PoC Analysis EPSS 0.07
Samedia Landshop - XSS
Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 17, 2012
CVE-2012-5889 EPSS 0.00
Alex Kellner Powermail < 1.6.4 - XSS
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 17, 2012
CVE-2012-5888 EPSS 0.00
Benjamin Mack Seo Basics < 0.8.1 - XSS
Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 17, 2012
CVE-2012-5856 EPSS 0.00
Uk-cookie - XSS
Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 17, 2012
CVE-2012-5883 EPSS 0.01
Mozilla Bugzilla - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore.swf, a similar issue to CVE-2010-4209.
CWE-79 Nov 16, 2012
CVE-2012-5882 EPSS 0.00
Yahoo Yui - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.
CWE-79 Nov 16, 2012
CVE-2012-5881 EPSS 0.00
Yahoo Yui - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.
CWE-79 Nov 16, 2012
CVE-2012-4189 EPSS 0.00
Mozilla Bugzilla - XSS
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.
CWE-79 Nov 16, 2012
CVE-2012-4612 EPSS 0.00
EMC RSA Data Protection Mgr <3.2.1 - XSS
Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 16, 2012
CVE-2012-5851 1 PoC Analysis EPSS 0.00
Apple Webkit < 22.0.1229.96 - XSS
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
CWE-79 Nov 15, 2012
CVE-2012-4955 EPSS 0.01
Dell OMSA <6.5.0.1-7.1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 15, 2012
CVE-2012-4851 EPSS 0.00
IBM WebSphere App Server <8.5.0.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
CWE-79 Nov 14, 2012
CVE-2012-4497 EPSS 0.00
Devsaran Elegant Theme - XSS
Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide URL.
CWE-79 Nov 02, 2012
CVE-2012-4493 EPSS 0.00
ROY Baxter Better Revisions - XSS
Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer better revisions" permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 02, 2012
CVE-2012-5705 EPSS 0.00
Drupal Hotblocks <6.x-1.8 - XSS
Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names."
CWE-79 Nov 01, 2012
CVE-2012-4939 1 PoC Analysis EPSS 0.10
SolarWinds Orion <3.0-HotFix1 - XSS
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
CWE-79 Oct 31, 2012