CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
42,514 results Clear all
CVE-2010-4913 1 PoC Analysis EPSS 0.03
ColdGen ColdUserGroup 1.06 - XSS
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 08, 2011
CVE-2010-4909 2 PoCs Analysis EPSS 0.01
PaysiteReviewCMS 1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.
CWE-79 Oct 08, 2011
CVE-2010-4907 1 PoC Analysis EPSS 0.05
Zenphoto 1.3 - XSS
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
CWE-79 Oct 08, 2011
CVE-2010-4901 1 PoC Analysis EPSS 0.06
MySource Matrix 3.28.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
CWE-79 Oct 08, 2011
CVE-2010-4896 EPSS 0.00
Member Management System 4.0 - XSS
Cross-site scripting (XSS) vulnerability in admin/index.asp in Member Management System 4.0 allows remote attackers to inject arbitrary web script or HTML via the REF_URL parameter.
CWE-79 Oct 08, 2011
CVE-2010-4895 1 PoC Analysis EPSS 0.07
chillyCMS 1.1.3 - XSS
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information.
CWE-79 Oct 08, 2011
CVE-2010-4893 1 PoC Analysis EPSS 0.02
FestOS 2.3b - XSS
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.
CWE-79 Oct 08, 2011
CVE-2011-3598 EPSS 0.01
phpPgAdmin <5.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page title, related to classes/Misc.php; or the (2) return_url or (3) return_desc parameter to display.php.
CWE-79 Oct 08, 2011
CVE-2011-2661 EPSS 0.00
Novell Groupwise - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
CWE-79 Oct 08, 2011
CVE-2011-2227 EPSS 0.01
Novell IDM <4.0.0 - XSS
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.
CWE-79 Oct 08, 2011
CVE-2011-1696 EPSS 0.01
Novell IDM <4.0.0 - XSS
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.
CWE-79 Oct 08, 2011
CVE-2010-4892 EPSS 0.00
TYPO3 powermail <1.5.5 - XSS
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.5.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 07, 2011
CVE-2010-4890 EPSS 0.00
Yet Another Calendar <1.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 07, 2011
CVE-2010-4886 EPSS 0.00
TYPO3 Tweet Button <1.0.5 - XSS
Cross-site scripting (XSS) vulnerability in the "official twitter tweet button for your page" (tweetbutton) extension before 1.0.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 07, 2011
CVE-2010-4885 EPSS 0.00
TYPO3 xing <1.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the XING Button (xing) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 07, 2011
CVE-2010-4883 1 PoC Analysis EPSS 0.08
MODx Revolution 2.0.2-pl - XSS
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.
CWE-79 Oct 07, 2011
CVE-2010-4882 1 PoC Analysis EPSS 0.03
Auto CMS 1.6 - XSS
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web script or HTML via the sitetitle parameter.
CWE-79 Oct 07, 2011
CVE-2010-4880 EPSS 0.00
ApPHP CAL - XSS
Multiple cross-site scripting (XSS) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to inject arbitrary web script or HTML via the (1) category_name, (2) category_description, (3) event_name, or (4) event_description parameter.
CWE-79 Oct 07, 2011
CVE-2010-4877 1 PoC Analysis EPSS 0.01
OneCMS 2.6.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.
CWE-79 Oct 07, 2011
CVE-2010-4875 1 PoC Analysis EPSS 0.02
Vodpod Video Gallery Plugin <3.1.5 - XSS
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.
CWE-79 Oct 07, 2011