CVE & Exploit Intelligence Database

Updated 27m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
42,532 results Clear all
CVE-2012-1215 EPSS 0.00
Yoono For Firefox < 7.7.7 - XSS
Cross-site scripting (XSS) vulnerability in the Add friends module in the Yoono extension before 7.7.8 for Firefox allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.
CWE-79 Feb 21, 2012
CVE-2012-1214 EPSS 0.00
Yoono Desktop < 1.8.20 - XSS
Cross-site scripting (XSS) vulnerability in the Add friends module in Yoono Desktop Application before 1.8.21 allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.
CWE-79 Feb 21, 2012
CVE-2011-5081 EPSS 0.01
Backuppc - XSS
Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or HTML via the share parameter in a RestoreFile action to index.cgi.
CWE-79 Feb 18, 2012
CVE-2011-4923 EPSS 0.01
Backuppc - XSS
Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.
CWE-79 Feb 18, 2012
CVE-2011-3361 EPSS 0.01
Backuppc - XSS
Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a browse action to index.cgi.
CWE-79 Feb 18, 2012
CVE-2012-0767 6.1 MEDIUM KEV EPSS 0.16
Adobe Flash Player <10.3.183.15,11.x<11.1.102.62 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
CWE-79 Feb 16, 2012
CVE-2012-0765 EPSS 0.02
Adobe RoboHelp <9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.
CWE-79 Feb 15, 2012
CVE-2012-0145 EPSS 0.36
Microsoft Sharepoint Server - XSS
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
CWE-79 Feb 14, 2012
CVE-2012-0144 EPSS 0.36
Microsoft Sharepoint Server - XSS
Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
CWE-79 Feb 14, 2012
CVE-2012-0017 EPSS 0.42
Microsoft Sharepoint Foundation - XSS
Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
CWE-79 Feb 14, 2012
CVE-2012-1087 EPSS 0.00
TYPO3 bc_post2facebook <0.2.2 - XSS
Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1086 EPSS 0.00
TYPO3 aeurltool 0.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the UrlTool (aeurltool) extension 0.1.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1084 EPSS 0.00
TYPO3 beuserswitch 0.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1082 EPSS 0.00
TYPO3 terminal <0.3.2 - XSS
Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1081 EPSS 0.00
TYPO3 ya_googlesearch <0.3.10 - XSS
Cross-site scripting (XSS) vulnerability in the Yet another Google search (ya_googlesearch) extension before 0.3.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1080 EPSS 0.00
Euro Calculator 0.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Euro Calculator (skt_eurocalc) extension 0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1076 EPSS 0.00
TYPO3 rtg_files <1.5.2 - XSS
Cross-site scripting (XSS) vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1073 EPSS 0.00
TYPO3 toi_category <0.6.0 - XSS
Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 14, 2012
CVE-2012-1070 EPSS 0.00
TYPO3 irfaq <1.1.4 - XSS
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parameter."
CWE-79 Feb 14, 2012
CVE-2012-1069 1 PoC Analysis EPSS 0.01
lknSupport - XSS
Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Feb 14, 2012