CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
42,509 results Clear all
CVE-2011-2754 EPSS 0.00
IBM Web Content Manager - XSS
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 17, 2011
CVE-2011-2510 EPSS 0.01
Dokuwiki < 2010-11-07a - XSS
Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.
CWE-79 Jul 14, 2011
CVE-2011-2023 EPSS 0.00
SquirrelMail <1.4.22 - XSS
Cross-site scripting (XSS) vulnerability in functions/mime.php in SquirrelMail before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via a crafted STYLE element in an e-mail message.
CWE-79 Jul 14, 2011
CVE-2010-4555 EPSS 0.01
Squirrelmail < 1.4.21 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than) character in the SquirrelSpell spellchecking plugin, and (3) errors associated with the Index Order (aka options_order) page.
CWE-79 Jul 14, 2011
CVE-2010-4813 EPSS 0.00
Drupal 6.x - XSS
Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.
CWE-79 Jul 08, 2011
CVE-2010-4811 EPSS 0.00
6kbbs 8.0 build 20100901 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ajaxmember.php in 6kbbs 8.0 build 20100901 allow remote attackers to inject arbitrary web script or HTML via the (1) user[msn], (2) user[email], and (3) user[phone] parameters in a modifyDetails action.
CWE-79 Jul 08, 2011
CVE-2011-2679 EPSS 0.00
IBM Rational Doors Web Access - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 07, 2011
CVE-2011-2609 EPSS 0.01
Opera Browser < 11.50 - XSS
Opera before 11.50 does not properly restrict data: URIs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
CWE-79 Jul 01, 2011
CVE-2011-2607 EPSS 0.00
IBM Rational Team Concert - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513.
CWE-79 Jun 30, 2011
CVE-2011-2606 EPSS 0.00
IBM Rational Team Concert - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.
CWE-79 Jun 30, 2011
CVE-2011-2369 EPSS 0.00
Mozilla Firefox - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.
CWE-79 Jun 30, 2011
CVE-2011-2197 EPSS 0.00
Ruby on Rails <2.3.12, <3.0.8, <3.1.0.rc2 - XSS
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
CWE-79 Jun 30, 2011
CVE-2011-2470 EPSS 0.00
Reallysimplechat Really Simple Chat - XSS
Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter.
CWE-79 Jun 29, 2011
CVE-2011-2180 EPSS 0.00
A Really Simple Chat <3.3-rc2 - XSS
Cross-site scripting (XSS) vulnerability in dereferer.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_link parameter.
CWE-79 Jun 29, 2011
CVE-2011-1335 EPSS 0.01
Cybozu Office <8.1.1 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user list functions."
CWE-79 Jun 29, 2011
CVE-2011-1334 EPSS 0.01
Cybozu - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the mail system."
CWE-79 Jun 29, 2011
CVE-2011-1333 EPSS 0.01
Cybozu Office 6-Cybozu Garoon 2.0.0-2.1.3 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the bulletin board system."
CWE-79 Jun 29, 2011
CVE-2011-1332 EPSS 0.00
Cybozu Garoon <2.1.3 - XSS
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-6570.
CWE-79 Jun 29, 2011
CVE-2011-1330 EPSS 0.00
WeblyGo <5.11 - XSS
Cross-site scripting (XSS) vulnerability in WeblyGo 5.0 Pro/LE, 5.02 Pro/LE, 5.03 Pro/LE, 5.04 Pro/LE, and 5.10 Pro/LE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 22, 2011
CVE-2011-1481 EPSS 0.00
PHP-Nuke <8.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_name or (2) sender_email parameter in a Feedback action to modules.php.
CWE-79 Jun 21, 2011