CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
42,514 results Clear all
CVE-2011-3635 EPSS 0.00
Empathy <3.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).
CWE-79 Oct 23, 2011
CVE-2011-4024 1 PoC Analysis EPSS 0.11
OCS Inventory NG <2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 21, 2011
CVE-2010-4966 EPSS 0.00
ATCOM Netvolution - XSS
Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search action.
CWE-79 Oct 21, 2011
CVE-2009-5103 1 PoC Analysis EPSS 0.00
Atcom Netvolution - XSS
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.
CWE-79 Oct 21, 2011
CVE-2011-3294 EPSS 0.00
Cisco Telepresence Video Communication Servers < x6.1 - XSS
Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, aka Bug ID CSCts80342.
CWE-79 Oct 19, 2011
CVE-2011-3426 EPSS 0.01
Safari <5 - XSS
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
CWE-79 Oct 14, 2011
CVE-2011-3254 EPSS 0.00
Apple Iphone OS - XSS
Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary web script or HTML via an invitation note.
CWE-79 Oct 14, 2011
CVE-2011-3243 EPSS 0.00
Apple Iphone OS - XSS
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
CWE-79 Oct 14, 2011
CVE-2011-3218 EPSS 0.01
Apple Mac OS X < 10.6.8 - XSS
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
CWE-79 Oct 14, 2011
CVE-2011-1897 EPSS 0.14
Microsoft Forefront UAG 2010 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
CWE-79 Oct 12, 2011
CVE-2011-1896 EPSS 0.10
Microsoft Forefront UAG 2010 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
CWE-79 Oct 12, 2011
CVE-2011-2675 EPSS 0.00
Utage.org Enkai < 030511 - XSS
Cross-site scripting (XSS) vulnerability in Enkai-kun before 110916 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 10, 2011
CVE-2010-4960 EPSS 0.00
TYPO3 - XSS
Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka Yellow Pages or mh_branchenbuch) extension before 0.9.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 09, 2011
CVE-2010-4956 EPSS 0.00
TYPO3 ke_questionnaire <2.2.3 - XSS
Cross-site scripting (XSS) vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 09, 2011
CVE-2010-4951 EPSS 0.00
TYPO3 vx_xajax_shoutbox <1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the xaJax Shoutbox (vx_xajax_shoutbox) extension before 1.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 09, 2011
CVE-2010-4949 1 PoC Analysis EPSS 0.04
Joomla! <2.1.2, FreiChat/FreiChatPure - XSS
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.
CWE-79 Oct 09, 2011
CVE-2010-4947 1 PoC Analysis EPSS 0.00
ALLPC 2.5 - XSS
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
CWE-79 Oct 09, 2011
CVE-2010-4932 EPSS 0.00
Entrans <0.3.3 - XSS
Cross-site scripting (XSS) vulnerability in search.php in Entrans before 0.3.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
CWE-79 Oct 09, 2011
CVE-2010-4930 1 PoC Analysis EPSS 0.05
@mail <6.2.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject arbitrary web script or HTML via the MailType parameter in a mail/auth/processlogin action.
CWE-79 Oct 09, 2011
CVE-2010-4928 1 PoC Analysis EPSS 0.01
Joomla! com_restaurantguide 1.0.0 - XSS
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing it after a > (greater than) character.
CWE-79 Oct 09, 2011