Exploit Intelligence Platform

Updated 53m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,175 CVEs tracked 53,341 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,943 Nuclei templates 49,090 vendors 42,769 researchers
42,551 results Clear all
CVE-2012-2985 EPSS 0.01
CuteSoft Cute Editor 6.4 - XSS
Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in CuteSoft Cute Editor 6.4 allows remote authenticated users to inject arbitrary web script or HTML via the _UploadID parameter.
CWE-79 Aug 21, 2012
CVE-2012-4238 EPSS 0.00
Tecnick Tcexam < 11.3.007 - XSS
Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.
CWE-79 Aug 20, 2012
CVE-2012-4052 EPSS 0.00
Jease < 2.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jease before 2.9, when creating a comment, allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, or (3) comment parameter.
CWE-79 Aug 20, 2012
CVE-2012-4236 1 PoC Analysis EPSS 0.06
Totalshopuk Ecommerce < 2.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Aug 20, 2012
CVE-2012-3296 EPSS 0.01
IBM Power HMC <7R7.1.0-7R7.3.0 - XSS
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 17, 2012
CVE-2012-2205 EPSS 0.00
IBM Rational Clearquest - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.
CWE-79 Aug 17, 2012
CVE-2012-2169 EPSS 0.00
IBM Rational Clearquest - XSS
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
CWE-79 Aug 17, 2012
CVE-2012-3308 EPSS 0.00
IBM Sametime - XSS
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.
CWE-79 Aug 17, 2012
CVE-2012-1908 EPSS 0.00
Splunk - XSS
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Aug 17, 2012
CVE-2012-1597 1 PoC Analysis EPSS 0.03
Ezjscore < 1.4 - XSS
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 17, 2012
CVE-2012-3251 EPSS 0.01
HP Service Manager/Center - XSS
Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 7.11, 9.21, and 9.30, and HP Service Center Web Tier 6.28, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 16, 2012
CVE-2012-4344 1 PoC Analysis EPSS 0.09
Progress Whatsup Gold - XSS
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.
CWE-79 Aug 15, 2012
CVE-2012-4342 EPSS 0.00
Menalto Gallery < 3.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 15, 2012
CVE-2012-4340 EPSS 0.00
Sybase Easerver < 6.0.2 - XSS
Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 15, 2012
CVE-2012-3434 EPSS 0.01
TOM Braider Count Per Day < 3.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.
CWE-79 Aug 15, 2012
CVE-2012-2769 EPSS 0.00
Best Practical Solutions RT <4.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the Extension::MobileUI extension before 1.02 for Best Practical Solutions RT 3.8.x and in Best Practical Solutions RT before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 15, 2012
CVE-2012-2768 EPSS 0.00
RTFM <2.4.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 15, 2012
CVE-2012-4037 EPSS 0.01
Transmission < 2.60 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.
CWE-79 Aug 15, 2012
CVE-2012-2570 2 PoCs Analysis EPSS 0.02
X-Cart Gold 4.5 - XSS
Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter.
CWE-79 Aug 15, 2012
CVE-2012-2154 EPSS 0.00
Kyle Browning Cdn2 Video - XSS
Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012