Exploit Intelligence Platform

Updated 53m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,175 CVEs tracked 53,341 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,943 Nuclei templates 49,090 vendors 42,769 researchers
42,551 results Clear all
CVE-2012-2082 EPSS 0.00
Chaos Tool Suite Ctools - XSS
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.
CWE-79 Aug 14, 2012
CVE-2012-2076 EPSS 0.00
ROB Loach Sharethis - XSS
Cross-site scripting (XSS) vulnerability in the administration forms in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with administer sharethis permissions to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-2075 EPSS 0.00
Steindom Contact Save - XSS
Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-2072 EPSS 0.00
Patrick Przybilla Addtoany - XSS
Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-2071 EPSS 0.00
Geoff Davies Contact Forms - XSS
Cross-site scripting (XSS) vulnerability in the Contact Forms module 6.x-1.x before 6.x-1.13 for Drupal when the core contact form is enabled, allows remote authenticated users with the administer site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-2070 EPSS 0.00
Andrew Levine Multiblock - XSS
Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block title.
CWE-79 Aug 14, 2012
CVE-2012-2300 EPSS 0.00
Ubercart - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product classes permission to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-2298 EPSS 0.01
Drupal Realname - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks."
CWE-79 Aug 14, 2012
CVE-2012-2209 1 PoC Analysis EPSS 0.04
Piwigo < 2.3.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuration module, (2) installstatus parameter in the languages_new module, or (3) theme parameter in the theme module.
CWE-79 Aug 14, 2012
CVE-2012-2151 EPSS 0.01
Spip - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 14, 2012
CVE-2012-1835 4 PoCs Analysis NUCLEI EPSS 0.01
Timely All-in-one Event Calendar - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to app/view/agenda-widget.php; (6) button_value parameter to app/view/box_publish_button.php; or (7) msg parameter to /app/view/save_successful.php.
CWE-79 Aug 14, 2012
CVE-2012-4283 EPSS 0.00
Netweblogic Login With Ajax < 3.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
CWE-79 Aug 13, 2012
CVE-2012-2331 1 PoC Analysis EPSS 0.15
Serendipity <1.6.1 - XSS
Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).
CWE-79 Aug 13, 2012
CVE-2012-2274 1 PoC Analysis EPSS 0.01
Pivotx < 2.3.2 - XSS
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
CWE-79 Aug 13, 2012
CVE-2012-4278 1 PoC Analysis EPSS 0.07
Rwcinc Free Realty - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) notes parameter to (a) admin/agenteditor.php; (2) title, (3) previewdesc, (4) fulldesc, or (5) notes parameter (b) to agentadmin.php or (c) in an addlisting action to agentadmin.php; or unspecified vectors to (d) admin/adminfeatures.php.
CWE-79 Aug 13, 2012
CVE-2012-4277 EPSS 0.00
Smarty < 3.1.7 - XSS
Cross-site scripting (XSS) vulnerability in the smarty_function_html_options_optoutput function in distribution/libs/plugins/function.html_options.php in Smarty before 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 13, 2012
CVE-2012-4275 EPSS 0.00
Hitachi IT Operations Director - XSS
Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Director 02-50-01 through 02-50-07, 03-00 before 03-00-08 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 13, 2012
CVE-2012-4273 NUCLEI EPSS 0.01
Ppfeufer 2-click-social-media-buttons < 0.33 - XSS
Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xing-url parameter.
CWE-79 Aug 13, 2012
CVE-2012-4272 EPSS 0.00
Ppfeufer 2-click-social-media-buttons < 0.33 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "processing of the buttons of Xing and Pinterest".
CWE-79 Aug 13, 2012
CVE-2012-4271 EPSS 0.00
Mark Jaquith Bad Behavior < 2.0.46 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in bad-behavior-wordpress-admin.php in the Bad Behavior plugin before 2.0.47 and 2.2.x before 2.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5) reverse_proxy_addresses, or (6) reverse_proxy_header parameter.
CWE-79 Aug 13, 2012