CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
42,514 results Clear all
CVE-2010-4874 1 PoC Analysis EPSS 0.08
NinkoBB 1.3 RC5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim parameter.
CWE-79 Oct 07, 2011
CVE-2010-4873 1 PoC Analysis EPSS 0.06
WeBid 0.8.5 P1 - XSS
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Oct 07, 2011
CVE-2010-4868 1 PoC Analysis EPSS 0.01
W-Agora <4.2.1 - XSS
Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.
CWE-79 Oct 05, 2011
CVE-2010-4863 1 PoC Analysis EPSS 0.04
GetSimple CMS 2.01 - XSS
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.
CWE-79 Oct 05, 2011
CVE-2011-0459 EPSS 0.00
Cyber-ark Password Vault Web Access < 5.0 - XSS
Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 05, 2011
CVE-2011-1221 EPSS 0.00
Realnetworks Realplayer - XSS
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.
CWE-79 Oct 04, 2011
CVE-2011-3979 1 PoC Analysis EPSS 0.10
Zikula Application Framework <1.3.0-1.2.7 - XSS
Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web script or HTML via the themename parameter in the setasdefault action to index.php.
CWE-79 Oct 04, 2011
CVE-2011-3978 EPSS 0.00
LightNEasy 3.2.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.
CWE-79 Oct 04, 2011
CVE-2011-3371 EPSS 0.01
PunBB <1.3.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in include/functions.php in PunBB before 1.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) form_sent, (3) csrf_token, (4) req_confirm, or (5) delete parameter to delete.php, the (6) id, (7) form_sent, (8) csrf_token, (9) req_message, or (10) submit parameter to edit.php, the (11) action, (12) form_sent, (13) csrf_token, (14) req_email, or (15) request_pass parameter to login.php, the (16) email, (17) form_sent, (18) redirect_url, (19) csrf_token, (20) req_subject, (21) req_message, or (22) submit parameter to misc.php, the (23) action, (24) id, (25) form_sent, (26) csrf_token, (27) req_old_password, (28) req_new_password1, (29) req_new_password2, or (30) update parameter to profile.php, or the (31) action, (32) form_sent, (33) csrf_token, (34) req_username, (35) req_password1, (36) req_password2, (37) req_email1, (38) timezone, or (39) register parameter to register.php.
CWE-79 Oct 02, 2011
CVE-2011-2673 EPSS 0.00
Basercms < 1.6.13.1 - XSS
Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 02, 2011
CVE-2011-0552 EPSS 0.01
Symantec IM Manager < 8.4.17 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.
CWE-79 Oct 02, 2011
CVE-2011-3010 2 PoCs Analysis EPSS 0.17
Twiki < 5.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.
CWE-79 Sep 30, 2011
CVE-2011-3865 1 PoC Analysis EPSS 0.00
WordPress <1.6 - XSS
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
CWE-79 Sep 28, 2011
CVE-2011-3864 EPSS 0.00
The Erudite <2.7.9 - XSS
Cross-site scripting (XSS) vulnerability in the The Erudite theme before 2.7.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.
CWE-79 Sep 28, 2011
CVE-2011-3863 1 PoC Analysis EPSS 0.00
WordPress RedLine <1.66 - XSS
Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Sep 28, 2011
CVE-2011-3862 1 PoC Analysis EPSS 0.00
Morning Coffee <3.6 - XSS
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
CWE-79 Sep 28, 2011
CVE-2011-3861 1 PoC Analysis EPSS 0.00
Web Minimalist 200901 - XSS
Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
CWE-79 Sep 28, 2011
CVE-2011-3860 1 PoC Analysis EPSS 0.00
Cover WP <1.6.6 - XSS
Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Sep 28, 2011
CVE-2011-3859 1 PoC Analysis EPSS 0.00
WordPress Trending <0.2 - XSS
Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.
CWE-79 Sep 28, 2011
CVE-2011-3858 1 PoC Analysis EPSS 0.00
Pixiv Custom <2.1.6 - XSS
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Sep 28, 2011