CVE & Exploit Intelligence Database

Updated 59m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
42,514 results Clear all
CVE-2011-3390 1 PoC Analysis EPSS 0.12
IBM OAT <2.72 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login action.
CWE-79 Sep 06, 2011
CVE-2011-3385 EPSS 0.00
WebsiteBaker <2.8 - XSS
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307.
CWE-79 Sep 02, 2011
CVE-2009-5086 EPSS 0.00
Juniper Idp - XSS
Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 02, 2011
CVE-2011-3132 EPSS 0.00
Tibco Spotfire Analytics Server < 10.0.1 - XSS
Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 02, 2011
CVE-2011-2932 EPSS 0.01
Rails < 2.3.13 - XSS
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping vulnerability."
CWE-79 Aug 29, 2011
CVE-2011-2931 EPSS 0.01
Rails < 2.3.13 - XSS
Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.
CWE-79 Aug 29, 2011
CVE-2011-3181 EPSS 0.01
Phpmyadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.
CWE-79 Aug 29, 2011
CVE-2011-2712 EPSS 0.05
Apache Wicket - XSS
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Aug 29, 2011
CVE-2010-4828 EPSS 0.03
SolarWinds Orion NPM 10.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName parameter to CustomChart.aspx.
CWE-79 Aug 24, 2011
CVE-2010-4827 EPSS 0.00
Snitz Forums 2000 3.4.07 - XSS
Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Aug 24, 2011
CVE-2010-4825 EPSS 0.00
WordPress wp-twitter-feed 0.3.1 - XSS
Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Aug 24, 2011
CVE-2011-2652 EPSS 0.00
Marcus Schafer Kiwi < 3.74.1 - XSS
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.
CWE-79 Aug 23, 2011
CVE-2011-2650 EPSS 0.00
Marcus Schafer Kiwi < 3.74.1 - XSS
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.
CWE-79 Aug 23, 2011
CVE-2011-2644 EPSS 0.00
Marcus Schafer Kiwi < 3.74.1 - XSS
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
CWE-79 Aug 23, 2011
CVE-2011-2226 EPSS 0.00
Kiwi <3.74.2 - XSS
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.
CWE-79 Aug 23, 2011
CVE-2011-2904 EPSS 0.01
Zabbix < 1.8.5 - XSS
Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.
CWE-79 Aug 19, 2011
CVE-2011-2410 EPSS 0.01
HP Openview Performance Insight - XSS
Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 19, 2011
CVE-2011-2947 EPSS 0.00
Realnetworks Realplayer - XSS
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.
CWE-79 Aug 18, 2011
CVE-2011-3144 EPSS 0.01
Aveva Clearscada < r4.5 - XSS
Cross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 16, 2011
CVE-2011-0550 EPSS 0.01
Symantec Endpoint Protection - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token parameter to portal/Help.jsp or (2) the URI in a console/apps/sepm request.
CWE-79 Aug 15, 2011