CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
42,527 results Clear all
CVE-2012-0909 EPSS 0.00
Horde Groupware Webmail <4.0.6 - XSS
Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.
CWE-79 Jan 24, 2012
CVE-2012-0908 EPSS 0.00
SimpleSAMLphp <1.8.2 - XSS
Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.
CWE-79 Jan 24, 2012
CVE-2012-0791 EXPLOITED EPSS 0.01
Horde IMP <5.0.18, Horde Groupware Webmail Edition <4.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 24, 2012
CVE-2012-0790 EPSS 0.00
Smokeping <2.6.7 - XSS
Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.
CWE-79 Jan 24, 2012
CVE-2012-0389 2 PoCs Analysis EPSS 0.34
MailEnable <6.03 - XSS
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.
CWE-79 Jan 24, 2012
CVE-2012-0040 EPSS 0.01
Simplesamlphp < 1.8.1 - XSS
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
CWE-79 Jan 24, 2012
CVE-2012-0285 1 PoC Analysis EPSS 0.01
Stoneware webNetwork <6.0.8.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 24, 2012
CVE-2012-0313 EPSS 0.00
glucose <6.2 - XSS
Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.
CWE-79 Jan 24, 2012
CVE-2012-0903 EPSS 0.00
Zimbra Desktop 7.1.2 b10978 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.
CWE-79 Jan 20, 2012
CVE-2012-0901 1 PoC Analysis NUCLEI EPSS 0.01
YouSayToo auto-publishing plugin 1.0 - XSS
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
CWE-79 Jan 20, 2012
CVE-2012-0900 1 PoC Analysis EPSS 0.04
Beehive Forum 1.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
CWE-79 Jan 20, 2012
CVE-2012-0899 1 PoC Analysis EPSS 0.00
Annuaire PHP - XSS
Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.
CWE-79 Jan 20, 2012
CVE-2012-0895 1 PoC Analysis EPSS 0.02
WordPress <3.1.1 - XSS
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.
CWE-79 Jan 20, 2012
CVE-2011-5065 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
CWE-79 Jan 15, 2012
CVE-2011-1362 EPSS 0.00
IBM WebSphere Application Server <6.1.0.41, <7.0.0.19 - XSS
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
CWE-79 Jan 15, 2012
CVE-2012-0696 EPSS 0.00
IBM Cognos TM1 <9.5 FP1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.
CWE-79 Jan 13, 2012
CVE-2012-0309 EPSS 0.01
Cogentdatahub Cascade Datahub < 6.4.20 - XSS
Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 13, 2012
CVE-2012-0007 1 PoC Analysis EPSS 0.59
Microsoft Anti-cross Site Scripting Library - XSS
The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."
CWE-79 Jan 10, 2012
CVE-2011-3206 EPSS 0.00
Redhat Jboss Operations Network < 2.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 08, 2012
CVE-2012-0287 EPSS 0.01
WordPress <3.3.1 - XSS
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
CWE-79 Jan 06, 2012