CVE & Exploit Intelligence Database

Updated 59m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
42,514 results Clear all
CVE-2011-3356 EPSS 0.01
Mantisbt < 1.2.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1) manage_config_email_page.php, (2) manage_config_workflow_page.php, or (3) bugs/plugin.php.
CWE-79 Sep 21, 2011
CVE-2011-2938 1 PoC Analysis EPSS 0.16
Mantisbt < 1.2.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.
CWE-79 Sep 21, 2011
CVE-2011-2937 EPSS 0.01
Roundcube Webmail < 0.5.3 - XSS
Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
CWE-79 Sep 21, 2011
CVE-2011-2672 EPSS 0.00
Christian Weiske Semanticscuttle < 0.97 - XSS
Cross-site scripting (XSS) vulnerability in SemanticScuttle before 0.98 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2011
CVE-2011-1510 EPSS 0.00
ManageEngine SDP <8012 - XSS
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.
CWE-79 Sep 20, 2011
CVE-2011-3576 EPSS 0.00
IBM Lotus Domino 8.5.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf.
CWE-79 Sep 19, 2011
CVE-2011-3423 EPSS 0.00
TIBCO - XSS
Cross-site scripting (XSS) vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 19, 2011
CVE-2011-3393 1 PoC Analysis EPSS 0.01
MYRE Real Estate Software - XSS
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter.
CWE-79 Sep 15, 2011
CVE-2011-1893 EPSS 0.59
Microsoft Office SharePoint Server 2010 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
CWE-79 Sep 15, 2011
CVE-2011-1891 EPSS 0.48
Microsoft Sharepoint Foundation - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
CWE-79 Sep 15, 2011
CVE-2011-1890 EPSS 0.35
Microsoft Sharepoint Foundation - XSS
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
CWE-79 Sep 15, 2011
CVE-2011-0653 EPSS 0.41
Microsoft Sharepoint Foundation - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
CWE-79 Sep 15, 2011
CVE-2010-4837 1 PoC Analysis EPSS 0.00
JSupport 1.5.6 - XSS
Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 14, 2011
CVE-2010-4836 1 PoC Analysis EPSS 0.01
PHPShop 2.1 EE - XSS
Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter.
CWE-79 Sep 14, 2011
CVE-2009-5099 EPSS 0.00
Pentaho BI Server < 1.7.0.1062 - XSS
Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attackers to inject arbitrary web script or HTML via the outputType parameter.
CWE-79 Sep 13, 2011
CVE-2009-5096 EPSS 0.00
Khalid Baheyeldin Flag Content - XSS
Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Reason parameter.
CWE-79 Sep 13, 2011
CVE-2009-5092 EPSS 0.14
Microsoft Fast Esp < 5.1.5 - XSS
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 12, 2011
CVE-2011-3392 EPSS 0.00
Phorum <5.2.17 - XSS
Cross-site scripting (XSS) vulnerability in control.php in the controlcenter in Phorum before 5.2.17 allows remote attackers to inject arbitrary web script or HTML via the real_name parameter.
CWE-79 Sep 08, 2011
CVE-2011-3384 EPSS 0.00
Sage add-on <1.3.10 - XSS
Cross-site scripting (XSS) vulnerability in the Sage add-on 1.3.10 and earlier for Firefox allows remote attackers to inject arbitrary web script or HTML via a crafted feed, a different vulnerability than CVE-2009-4102.
CWE-79 Sep 08, 2011
CVE-2011-3382 EPSS 0.00
Phorum <5.2.16 - XSS
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 08, 2011