CVE & Exploit Intelligence Database

Updated 10m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
42,527 results Clear all
CVE-2011-4274 EPSS 0.00
Movable Type <3.1 - XSS
Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-2676.
CWE-79 Nov 03, 2011
CVE-2011-4273 3 PoCs Analysis EPSS 0.01
GoAhead Webserver 2.18 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter to goform/AddUser, related to adduser.asp.
CWE-79 Nov 03, 2011
CVE-2010-5045 1 PoC Analysis EPSS 0.00
Smart ASP Survey - XSS
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
CWE-79 Nov 02, 2011
CVE-2010-5042 1 PoC Analysis EPSS 0.00
DJ-ArtGallery 0.9.1 - XSS
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 02, 2011
CVE-2010-5035 1 PoC Analysis EPSS 0.05
iScripts eSwap 2.0 - XSS
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.
CWE-79 Nov 02, 2011
CVE-2010-5031 EPSS 0.00
fileNice 1.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in fileNice 1.1 allows remote attackers to inject arbitrary web script or HTML via the sstring parameter (aka the Search Box). NOTE: some of these details are obtained from third party information.
CWE-79 Nov 02, 2011
CVE-2010-5030 EPSS 0.01
Ecomat CMS 5.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter in a web action.
CWE-79 Nov 02, 2011
CVE-2010-5027 1 PoC Analysis EPSS 0.05
Science Fair In A Box <2.0.6, 2.2.0 - XSS
Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 02, 2011
CVE-2010-5025 1 PoC Analysis EPSS 0.04
CuteSITE CMS <1.5.0 - XSS
Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 02, 2011
CVE-2010-5018 1 PoC Analysis EPSS 0.03
2daybiz Online Classified Script - XSS
Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
CWE-79 Nov 02, 2011
CVE-2010-5010 1 PoC Analysis EPSS 0.05
SchoolMation 2.3 - XSS
Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.
CWE-79 Nov 02, 2011
CVE-2010-5007 1 PoC Analysis EPSS 0.04
UTStats Beta <4 - XSS
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter.
CWE-79 Nov 02, 2011
CVE-2010-5005 EPSS 0.00
Rayzz Photoz - XSS
Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 02, 2011
CVE-2010-4971 1 PoC Analysis EPSS 0.02
VideoWhisper PHP - XSS
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.
CWE-79 Nov 02, 2011
CVE-2011-4074 1 PoC Analysis EPSS 0.12
phpLDAPadmin <1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
CWE-79 Nov 02, 2011
CVE-2011-3320 EPSS 0.00
Intelligent Platforms Proficy Historian < 4.0 - XSS
Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Nov 02, 2011
CVE-2010-5002 1 PoC Analysis EPSS 0.06
Exponent CMS 0.97.0 - XSS
Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter.
CWE-79 Nov 01, 2011
CVE-2010-4985 1 PoC Analysis EPSS 0.02
My Kazaam Notes Management System - XSS
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.
CWE-79 Nov 01, 2011
CVE-2010-4978 1 PoC Analysis EPSS 0.03
CANDID - XSS
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
CWE-79 Nov 01, 2011
CVE-2010-4976 1 PoC Analysis EPSS 0.04
MetInfo 3.0 - XSS
Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.
CWE-79 Nov 01, 2011