CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
42,527 results Clear all
CVE-2011-4616 EPSS 0.01
Igor Vlasenko Html-template-pro < 0.9506 - XSS
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.
CWE-79 Jan 06, 2012
CVE-2011-5019 1 PoC Analysis EPSS 0.03
Textpattern - XSS
Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.
CWE-79 Jan 05, 2012
CVE-2011-4920 EPSS 0.01
E107 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107_images/thumb.php or (2) rate.php, (3) resend_name parameter to e107_admin/users.php, and (4) link BBCode in user signatures.
CWE-79 Jan 04, 2012
CVE-2007-6751 EPSS 0.00
Movable Type <1.20 - XSS
Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 04, 2012
CVE-2011-5048 EPSS 0.00
IBM Web Experience Factory - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo.
CWE-79 Jan 03, 2012
CVE-2011-5047 EPSS 0.00
Pfsense < 2.0 - XSS
Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.
CWE-79 Jan 03, 2012
CVE-2011-4778 EPSS 0.00
Splunk - XSS
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.2.x before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPL-44614.
CWE-79 Jan 03, 2012
CVE-2011-3657 EPSS 0.00
Bugzilla <4.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) tabular report, (2) graphical report, or (3) new chart.
CWE-79 Jan 02, 2012
CVE-2011-5045 1 PoC Analysis EPSS 0.00
Jjwdesign Php Booking Calendar - XSS
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.
CWE-79 Dec 30, 2011
CVE-2011-5042 EPSS 0.00
Gphemsley Sasha - XSS
Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original disclosure also mentions the section_title parameter, but this was disputed by the vendor and retracted by the original researcher.
CWE-79 Dec 30, 2011
CVE-2011-5041 1 PoC Analysis EPSS 0.00
Pulsecms Pulse Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action and (2) post_id parameter in an edit-post action to index.php.
CWE-79 Dec 30, 2011
CVE-2011-5040 1 PoC Analysis EPSS 0.02
Infoproject Biznis Heroj - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php.
CWE-79 Dec 30, 2011
CVE-2011-5030 EPSS 0.00
Valthbald Meta Tags Quick - XSS
Cross-site scripting (XSS) vulnerability in the Meta tags quick module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, probably related to "names of entity bundles."
CWE-79 Dec 29, 2011
CVE-2011-5029 EPSS 0.00
Alexander Palmo Simple Php Blog < 0.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php.
CWE-79 Dec 29, 2011
CVE-2011-5027 EPSS 0.00
Zabbix < 1.8.10 - XSS
Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the profiler.
CWE-79 Dec 29, 2011
CVE-2011-4615 EPSS 0.01
Zabbix < 1.8.10 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.
CWE-79 Dec 29, 2011
CVE-2011-5025 2 PoCs Analysis EPSS 0.00
Yaws - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.
CWE-79 Dec 29, 2011
CVE-2011-5024 EPSS 0.00
GNU Mailman - XSS
Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.
CWE-79 Dec 29, 2011
CVE-2011-5023 1 PoC Analysis EPSS 0.00
Pligg Cms - XSS
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.
CWE-79 Dec 29, 2011
CVE-2011-5026 1 PoC Analysis EPSS 0.00
Winn Guestbook < 2.4.8c - XSS
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 29, 2011