Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
42,560 results Clear all
CVE-2012-1564 EPSS 0.00
Yuriy V Semenikhin Yvs Image Gallery - XSS
Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 06, 2012
CVE-2012-0986 EPSS 0.01
ImpressCMS <1.2.7-1.3.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.
CWE-79 Oct 06, 2012
CVE-2012-5050 EPSS 0.00
VMware vCenter Operations <5.0.x - XSS
Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 05, 2012
CVE-2012-4018 EPSS 0.00
Finalbeta Mywebsearch < 1.22 - XSS
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
CWE-79 Oct 05, 2012
CVE-2012-5296 EPSS 0.00
Mavili Guestbook - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.
CWE-79 Oct 04, 2012
CVE-2012-5295 1 PoC Analysis EPSS 0.01
FuseTalk Forums <3.2 - XSS
Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter.
CWE-79 Oct 04, 2012
CVE-2011-5207 1 PoC Analysis EPSS 0.04
Thecartpress < 1.1.6 - XSS
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.
CWE-79 Oct 04, 2012
CVE-2011-5206 EPSS 0.00
Rapidleech < 2.3 - XSS
Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter.
CWE-79 Oct 04, 2012
CVE-2011-5205 EPSS 0.00
Rapidleech < 2.3 - XSS
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.
CWE-79 Oct 04, 2012
CVE-2012-4242 1 PoC Analysis NUCLEI EPSS 0.08
MF Gig Calendar - XSS
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
CWE-79 Oct 01, 2012
CVE-2012-1604 1 PoC Analysis EPSS 0.06
Nextbbs - XSS
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php.
CWE-79 Oct 01, 2012
CVE-2012-1470 1 PoC Analysis EPSS 0.07
Ocportal < 7.1.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters.
CWE-79 Oct 01, 2012
CVE-2012-5233 EPSS 0.00
Drupal stickynote <7.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.
CWE-79 Oct 01, 2012
CVE-2012-0989 1 PoC Analysis EPSS 0.01
OneOrZero AIMS 2.8.0 - XSS
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
CWE-79 Oct 01, 2012
CVE-2012-5232 EPSS 0.00
Joomla! - XSS
Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 01, 2012
CVE-2012-5229 1 PoC Analysis EPSS 0.01
WordPress Slideshow Gallery2 - XSS
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter.
CWE-79 Oct 01, 2012
CVE-2012-5228 1 PoC Analysis EPSS 0.04
phplist <2.10.19 - XSS
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 01, 2012
CVE-2012-5226 1 PoC Analysis EPSS 0.00
Peel SHOPPING <2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php.
CWE-79 Oct 01, 2012
CVE-2012-5225 1 PoC Analysis EPSS 0.04
xClick Cart <1.0.2 - XSS
Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.
CWE-79 Oct 01, 2012
CVE-2012-1898 1 PoC Analysis EPSS 0.02
Ivano Binetti Wolf Cms < 0.75 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.
CWE-79 Oct 01, 2012