Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
42,560 results Clear all
CVE-2012-4532 EPSS 0.00
Joomla! <2.5.7 - XSS
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 31, 2012
CVE-2012-4531 EPSS 0.00
Joomla! <2.5.7 - XSS
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 31, 2012
CVE-2012-4496 EPSS 0.00
Inclind Custom Pub - XSS
Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject arbitrary web script or HTML via the status labels parameter.
CWE-79 Oct 31, 2012
CVE-2012-4492 EPSS 0.00
Isaac Sukin Shorten - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors to the (1) report or (2) Custom Services List page.
CWE-79 Oct 31, 2012
CVE-2012-4490 EPSS 0.00
Ricky Morse Excluded Users - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) user name or (2) email address.
CWE-79 Oct 31, 2012
CVE-2012-4485 EPSS 0.00
Manuel Garcia Galleryformatter < 7.x-1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a node or entity to inject arbitrary web script or HTML via the (1) title or (2) alt parameter.
CWE-79 Oct 31, 2012
CVE-2012-4484 EPSS 0.00
Trexart Campaignmonitor < 6.x-2.4 - XSS
Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).
CWE-79 Oct 31, 2012
CVE-2012-4547 NUCLEI EPSS 0.32
AWStats <7.1 - Unknown Vuln
Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.
CWE-79 Oct 31, 2012
CVE-2012-4195 EPSS 0.01
Mozilla Firefox < 10.0.10 - XSS
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.
CWE-79 Oct 29, 2012
CVE-2012-4194 EPSS 0.01
Mozilla Firefox < 16.0.2 - XSS
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
CWE-79 Oct 29, 2012
CVE-2012-4019 EPSS 0.00
C61 Tokyo Bbs - XSS
Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on Girls Interface (CGI) Tokyo BBS allows remote attackers to inject arbitrary web script or HTML via vectors related to the error page.
CWE-79 Oct 26, 2012
CVE-2011-5228 1 PoC Analysis EPSS 0.06
Apprain - XSS
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.
CWE-79 Oct 25, 2012
CVE-2011-5225 EPSS 0.00
Trioniclabs Sentinel - XSS
Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Oct 25, 2012
CVE-2011-5223 EPSS 0.01
Cacti < 0.8.7h - XSS
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CWE-79 Oct 25, 2012
CVE-2011-5221 EPSS 0.01
Websvn < 2.3.0 - XSS
Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.
CWE-79 Oct 25, 2012
CVE-2011-5220 EPSS 0.00
Cristopher SHI Php-scms < 1.6.8 - XSS
Cross-site scripting (XSS) vulnerability in templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter to index.php.
CWE-79 Oct 25, 2012
CVE-2011-5214 4 PoCs Analysis EPSS 0.08
Browsercrm < 5.100.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
CWE-79 Oct 25, 2012
CVE-2012-5368 EPSS 0.01
phpMyAdmin <3.5.3 - XSS
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.
CWE-79 Oct 25, 2012
CVE-2012-5339 EPSS 0.00
phpMyAdmin <3.5.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.
CWE-79 Oct 25, 2012
CVE-2012-5388 1 PoC Analysis EPSS 0.01
White Label CMS <1.5 - XSS
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related issue to CVE-2012-5387.
CWE-79 Oct 24, 2012