CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
42,532 results Clear all
CVE-2012-1982 EPSS 0.00
Socialcms < 1.0.2 - XSS
Cross-site scripting (XSS) vulnerability in my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the TR_title parameter in an edit action.
CWE-79 Apr 05, 2012
CVE-2012-0327 EPSS 0.00
Redmine <1.3.2 - XSS
Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 05, 2012
CVE-2012-0132 EPSS 0.01
HP Business Availability Center - XSS
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 05, 2012
CVE-2012-0225 EPSS 0.01
Invensys Wonderware Information Server - XSS
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 02, 2012
CVE-2011-5084 EPSS 0.00
Sixapart Movable Type - XSS
Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 02, 2012
CVE-2011-3058 EPSS 0.01
Google Chrome < 18.0.1025.142 - XSS
Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CWE-79 Mar 30, 2012
CVE-2012-0047 EPSS 0.01
Apache Wicket - XSS
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
CWE-79 Mar 23, 2012
CVE-2012-1842 EPSS 0.02
Quantum Scalar I500 Firmware < i7.0.2 - XSS
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 22, 2012
CVE-2012-0719 EPSS 0.00
IBM Tivoli Endpoint Manager <8.2.3 - XSS
Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.
CWE-79 Mar 22, 2012
CVE-2012-0399 EPSS 0.00
EMC RSA enVision <4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 20, 2012
CVE-2012-1039 4 PoCs Analysis EPSS 0.03
Dotclear <2.4.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
CWE-79 Mar 19, 2012
CVE-2012-0872 EPSS 0.01
OxWall <1.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, (3) form_name, (4) password, (5) realname, (6) repeatPassword, or (7) username parameters to Oxwall/join; (8) captcha, (9) email, (10) form_name, (11) from, or (12) subject parameters to Oxwall/contact; (13) tag parameter to Oxwall/blogs/browse-by-tag; or (14) PATH_INFO to Oxwall/photo/viewlist/tagged, (15) Oxwall/photo/viewlist, or (16) Oxwall/video/viewlist.
CWE-79 Mar 19, 2012
CVE-2012-1789 EPSS 0.00
Tskynet Kongreg8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.
CWE-79 Mar 19, 2012
CVE-2012-1788 EPSS 0.00
Wonderdesk Sql - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web script or HTML via the (1) cus_email parameter in a cust_lostpw action; or (2) help_name, (3) help_email, (4) help_website, or (5) help_example_url parameters in an hd_modify_record action.
CWE-79 Mar 19, 2012
CVE-2012-1787 1 PoC Analysis EPSS 0.05
Webglimpse < 2.20.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.
CWE-79 Mar 19, 2012
CVE-2012-1782 1 PoC Analysis EPSS 0.02
Osqa - XSS
Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.
CWE-79 Mar 19, 2012
CVE-2012-1781 EPSS 0.00
Socialcms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) TREF_email_address or (2) TR_name parameters.
CWE-79 Mar 19, 2012
CVE-2012-1779 EPSS 0.00
Idevspot Idev-businessdirectory - XSS
Cross-site scripting (XSS) vulnerability in IDevSpot idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter to index.php.
CWE-79 Mar 19, 2012
CVE-2011-5082 EPSS 0.00
S2member < 111216 - XSS
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
CWE-79 Mar 19, 2012
CVE-2009-5113 EPSS 0.00
Iwork Webglimpse < 2.18.7 - XSS
Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the DOC parameter.
CWE-79 Mar 19, 2012