Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,175 CVEs tracked 53,341 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,943 Nuclei templates 49,090 vendors 42,769 researchers
42,551 results Clear all
CVE-2012-4923 3 PoCs Analysis EPSS 0.03
Endian Firewall 2.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
CWE-79 Sep 15, 2012
CVE-2012-4336 1 PoC Analysis EPSS 0.01
Mike Carr Flogr < 2.5.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.
CWE-79 Sep 15, 2012
CVE-2012-3233 1 PoC Analysis EPSS 0.01
Kayako Fusion <4.50.1581 - XSS
Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Sep 15, 2012
CVE-2011-5176 EPSS 0.00
Bananadance Banana Dance < 1.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Banana Dance, possibly B.1.5 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) category parameter.
CWE-79 Sep 15, 2012
CVE-2012-4360 EPSS 0.00
Google Mod Pagespeed - XSS
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 15, 2012
CVE-2012-4905 1 PoC Analysis EPSS 0.01
Google Chrome <18.0.1025308 - XSS
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."
CWE-79 Sep 13, 2012
CVE-2012-4904 EPSS 0.00
Google Chrome <18.0.1025308 - XSS
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.
CWE-79 Sep 13, 2012
CVE-2012-2975 EPSS 0.01
F5 ASM <11.2.0 HF2 - XSS
Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page.
CWE-79 Sep 11, 2012
CVE-2012-2536 EPSS 0.44
Microsoft System Center Configuration Manager - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
CWE-79 Sep 11, 2012
CVE-2012-1892 EPSS 0.45
Microsoft Visual Studio Team Foundation Server - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
CWE-79 Sep 11, 2012
CVE-2012-4892 EPSS 0.00
FlatnuX CMS <2012-03.08 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2012-03.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title_en, (2) summary_en, or (3) body_en parameter in a submitnews action to the news module, a different vulnerability than CVE-2012-4890. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Sep 10, 2012
CVE-2012-4891 1 PoC Analysis EPSS 0.04
ManageEngine Firewall Analyzer 7.2 - XSS
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Sep 10, 2012
CVE-2012-4890 EPSS 0.01
FlatnuX CMS <2011 08.09.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.
CWE-79 Sep 10, 2012
CVE-2012-4889 5 PoCs Analysis NUCLEI EPSS 0.04
ManageEngine Firewall Analyzer 7.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.
CWE-79 Sep 10, 2012
CVE-2012-3326 EPSS 0.00
IBM Change And Configuration Management Database - XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 10, 2012
CVE-2012-3313 EPSS 0.00
IBM Change And Configuration Management Database - XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 10, 2012
CVE-2012-0746 EPSS 0.00
IBM Maximo Asset Mgmt 7.5 - XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 10, 2012
CVE-2012-1912 1 PoC Analysis EPSS 0.09
Chatelao Php Address Book < 7.0 - XSS
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.
CWE-79 Sep 09, 2012
CVE-2012-1648 EPSS 0.00
Danielb Cool Aid < 6.x-1.8 - XSS
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 09, 2012
CVE-2012-1582 EPSS 0.01
Mediawiki - XSS
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
CWE-79 Sep 09, 2012