CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
42,532 results Clear all
CVE-2012-2914 1 PoC Analysis EPSS 0.02
Unijimpe Captcha - XSS
Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 May 21, 2012
CVE-2012-2913 2 PoCs Analysis EPSS 0.01
Leaflet plugin <0.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.
CWE-79 May 21, 2012
CVE-2012-2912 EPSS 0.00
LeagueManager 3.7 - WordPress XSS
Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter in the show-league page or (2) season parameter in the team page to wp-admin/admin.php.
CWE-79 May 21, 2012
CVE-2012-2911 1 PoC Analysis EPSS 0.04
SiliSoftware backupDB <1.2.7a - XSS
Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or HTML via the onlyDB parameter.
CWE-79 May 21, 2012
CVE-2012-2910 2 PoCs Analysis EPSS 0.02
SiliSoftware phpThumb() <1.7.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter to demo/phpThumb.demo.random.php or (2) title parameter to demo/phpThumb.demo.showpic.php.
CWE-79 May 21, 2012
CVE-2012-2909 1 PoC Analysis EPSS 0.02
Viscacha 0.8.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in Kommentar.
CWE-79 May 21, 2012
CVE-2012-2907 EPSS 0.01
Aberdeen theme <6.x-1.11 - XSS
Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.
CWE-79 May 21, 2012
CVE-2012-2906 1 PoC Analysis EPSS 0.16
Artiphp CMS 5.5.0 Neo - XSS
Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to inject arbitrary web script or HTML via the (1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4) titre_sav, or (5) z39d27af885b32758ac0e7d4014a61561 parameter.
CWE-79 May 21, 2012
CVE-2012-2904 1 PoC Analysis EPSS 0.01
LongTail JW Player 5.9 - XSS
player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter.
CWE-79 May 21, 2012
CVE-2012-2903 1 PoC Analysis EPSS 0.01
PHP Address Book <7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php.
CWE-79 May 21, 2012
CVE-2012-2901 EPSS 0.00
Joomla JCE <2.1 - XSS
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.
CWE-79 May 21, 2012
CVE-2012-1247 EPSS 0.00
Webcreate Web Mart - XSS
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.
CWE-79 May 15, 2012
CVE-2012-1246 EPSS 0.00
Webcreate Web Mart < 1.7 - XSS
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.
CWE-79 May 15, 2012
CVE-2012-2008 EPSS 0.01
HP Performance Insight - XSS
Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 09, 2012
CVE-2012-1190 EPSS 0.00
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
CWE-79 May 03, 2012
CVE-2012-0737 EPSS 0.00
IBM Rational AppScan Enterprise <8.5.0.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 03, 2012
CVE-2012-2005 EPSS 0.01
HP Insight Management Agents < 8.70.0.0 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 02, 2012
CVE-2012-2001 EPSS 0.01
HP Snmp Agents For Linux < 8.7.0 - XSS
Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 02, 2012
CVE-2011-3317 EPSS 0.00
Cisco Secure Access Control Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.
CWE-79 May 02, 2012
CVE-2012-1245 EPSS 0.00
Osqa < 0.9.0 - XSS
Cross-site scripting (XSS) vulnerability in the cleanup_urls function in forum/utils/html.py in OSQA before 1234, and 0.9.0 Beta 3 and earlier, allows remote attackers to inject arbitrary web script or HTML via vectors related to a crafted URI.
CWE-79 Apr 27, 2012