Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
42,560 results Clear all
CVE-2012-5099 1 PoC Analysis EPSS 0.00
PHPB2B <4.1 - XSS
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
CWE-79 Sep 23, 2012
CVE-2011-5199 EPSS 0.00
Steveyolam Tinyguestbook - XSS
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CWE-79 Sep 23, 2012
CVE-2011-5194 EPSS 0.01
Phpace Samswhois < 1.4.2.3 - XSS
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.
CWE-79 Sep 23, 2012
CVE-2011-5193 1 PoC Analysis EPSS 0.01
Phpace Samswhois < 1.4.2.3 - XSS
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.
CWE-79 Sep 23, 2012
CVE-2011-5192 EPSS 0.00
Blairwilliams Pretty Link Lite Plugin < 1.5.5 - XSS
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.
CWE-79 Sep 23, 2012
CVE-2011-5191 EPSS 0.00
Blairwilliams Pretty Link Lite Plugin < 1.5.2 - XSS
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5192.
CWE-79 Sep 23, 2012
CVE-2011-5190 EPSS 0.00
Clonemonster Social Book Facebook Clone Monster - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php.
CWE-79 Sep 20, 2012
CVE-2011-5189 EPSS 0.00
Svendecabooter Webform Validation - XSS
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2012
CVE-2011-5188 EPSS 0.00
Tag1consulting Support Timer - XSS
Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2012
CVE-2011-5187 EPSS 0.00
Tag1consulting Support - XSS
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2012
CVE-2011-5186 1 PoC Analysis EPSS 0.01
Burnsy Jbshop Plugin - XSS
Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.
CWE-79 Sep 20, 2012
CVE-2011-5185 1 PoC Analysis EPSS 0.01
Realmatrix Online Subtitles Workshop < 2.0 - XSS
Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
CWE-79 Sep 20, 2012
CVE-2011-5184 5 PoCs Analysis EPSS 0.03
HP Network Node Manager I - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5) nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate. NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.
CWE-79 Sep 20, 2012
CVE-2011-5182 1 PoC Analysis EPSS 0.02
Wordpress Lanoba Social Plugin - XSS
Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf.
CWE-79 Sep 20, 2012
CVE-2011-5181 1 PoC Analysis NUCLEI EPSS 0.02
Clickdesk Live Support-live Chat Plugin - XSS
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 20, 2012
CVE-2011-5180 1 PoC Analysis EPSS 0.02
Zooeffect - XSS
Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party.
CWE-79 Sep 20, 2012
CVE-2011-5179 1 PoC Analysis NUCLEI EPSS 0.02
Skysa App Bar Integration Plugin < 1.03 - XSS
Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
CWE-79 Sep 20, 2012
CVE-2011-5178 EPSS 0.01
Infoblox Netmri < 6.2.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in netmri/config/userAdmin/login.tdf in Infoblox NetMRI 6.0.2.42, 6.1.2, 6.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) eulaAccepted or (2) mode parameter.
CWE-79 Sep 20, 2012
CVE-2011-5177 1 PoC Analysis EPSS 0.01
Esyndicat Pro - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort parameter to the search page.
CWE-79 Sep 20, 2012
CVE-2012-1630 EPSS 0.00
Nestor Mata Cuthbert Taxonomy Navigator - XSS
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2012