CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,076 CVEs tracked 53,339 with exploits 4,745 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,076 vendors 42,752 researchers
42,546 results Clear all
CVE-2012-3843 EPSS 0.00
E107 - XSS
Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 03, 2012
CVE-2012-3842 EPSS 0.00
Directadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.
CWE-79 Jul 03, 2012
CVE-2012-3840 1 PoC Analysis EPSS 0.05
Myclientbase - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name or (2) last_name parameters.
CWE-79 Jul 03, 2012
CVE-2012-3837 1 PoC Analysis EPSS 0.06
Babygekko Baby Gekko < 1.2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email_address, (3) password, (4) password_verify, (5) firstname, (6) lastname, or (7) verification_code parameter to users/action/register. NOTE: some of these details are obtained from third party information.
CWE-79 Jul 03, 2012
CVE-2012-3836 1 PoC Analysis EPSS 0.06
Babygekko Baby Gekko < 1.1.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) groupname parameter in a savecategory in the users module; (2) virtual_filename, (3) branch, (4) contact_person, (5) street, (6) city, (7) province, (8) postal, (9) country, (10) tollfree, (11) phone, (12) fax, or (13) mobile parameter in a saveitem action in the contacts module; (14) title parameter in a savecategory action in the menus module; (15) firstname or (16) lastname in a saveitem action in the users module; (17) meta_key or (18) meta_description in a saveitem action in the blog module; or (19) the PATH_INFO to admin/index.php.
CWE-79 Jul 03, 2012
CVE-2012-3835 2 PoCs Analysis EPSS 0.27
Alienvault Open Source Security Information Management - XSS
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.
CWE-79 Jul 03, 2012
CVE-2012-3833 EPSS 0.00
Opensolution Quick.cms - XSS
Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
CWE-79 Jul 03, 2012
CVE-2012-3832 EPSS 0.00
Milesj Decoda < 3.1 - XSS
Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags.
CWE-79 Jul 03, 2012
CVE-2012-3831 1 PoC Analysis EPSS 0.01
Milesj Decoda < 3.3 - XSS
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag.
CWE-79 Jul 03, 2012
CVE-2012-3830 1 PoC Analysis EPSS 0.04
Milesj Decoda < 3.3.1 - XSS
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive.
CWE-79 Jul 03, 2012
CVE-2012-3828 EPSS 0.00
Joomla! - XSS
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the Host HTTP Header.
CWE-79 Jul 03, 2012
CVE-2012-2698 1 PoC Analysis EPSS 0.14
MediaWiki <1.17.5, <1.18.4, <1.19.1 - XSS
Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.
CWE-79 Jun 29, 2012
CVE-2012-3232 1 PoC Analysis EPSS 0.00
web@all <2.0 - XSS
Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote attackers to inject arbitrary web script or HTML via the _text[title] parameter.
CWE-79 Jun 29, 2012
CVE-2012-2717 EPSS 0.01
Drupal Mobile Tools 6.x-2.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) Mobile URL field or (2) Desktop URL field to the General configuration page, or the (3) message to the Mobile Tools block message options.
CWE-79 Jun 27, 2012
CVE-2011-4956 EPSS 0.01
Wordpress < 3.1 - XSS
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 27, 2012
CVE-2011-4940 EPSS 0.00
Python < 2.5.6 - XSS
The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.
CWE-79 Jun 27, 2012
CVE-2012-3800 EPSS 0.00
Moshe Weitzman Organic Groups - XSS
Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.
CWE-79 Jun 27, 2012
CVE-2012-2726 EPSS 0.00
Drupal Protest <7.x-1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer protest" permission to inject arbitrary web script or HTML via the protest_body parameter.
CWE-79 Jun 27, 2012
CVE-2012-2723 EPSS 0.00
Maestro module <7.x-1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 27, 2012
CVE-2012-2715 EPSS 0.01
Amadou theme module <6.x-1.3 - XSS
Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.
CWE-79 Jun 27, 2012