CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
42,509 results Clear all
CVE-2011-1129 EPSS 0.00
Simplemachines Smf < 1.1.12 - XSS
Cross-site scripting (XSS) vulnerability in the EditNews function in ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, might allow remote authenticated users to inject arbitrary web script or HTML via a save_items action.
CWE-79 Jun 21, 2011
CVE-2011-1894 EPSS 0.14
Microsoft Windows - XSS
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
CWE-79 Jun 16, 2011
CVE-2011-1264 EPSS 0.02
Microsoft Windows 2003 Server - XSS
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
CWE-79 Jun 16, 2011
CVE-2011-1252 6.1 MEDIUM EPSS 0.19
Microsoft Internet Explorer - XSS
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
CWE-79 Jun 16, 2011
CVE-2011-2477 EPSS 0.00
Icinga < 1.4.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.
CWE-79 Jun 14, 2011
CVE-2011-2476 EPSS 0.00
Coppermine-gallery Coppermine Photo Gallery - XSS
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.
CWE-79 Jun 14, 2011
CVE-2011-2179 1 PoC Analysis EPSS 0.30
Nagios 3.2.3-Icinga <1.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
CWE-79 Jun 14, 2011
CVE-2011-1862 EPSS 0.01
HP Service Manager <9.21 - XSS
Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 14, 2011
CVE-2010-4667 EPSS 0.00
Coppermine-gallery Coppermine Photo Gallery < 1.4.26 - XSS
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 14, 2011
CVE-2011-2342 EPSS 0.00
Google Chrome < 12.0.742.91 - XSS
The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CWE-79 Jun 09, 2011
CVE-2011-1819 EPSS 0.00
Google Chrome <12.0.742.91 - Code Injection
Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.
CWE-79 Jun 09, 2011
CVE-2011-1815 EPSS 0.00
Google Chrome <12.0.742.91 - XSS
Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.
CWE-79 Jun 09, 2011
CVE-2011-2107 EXPLOITED EPSS 0.01
Adobe Flash Player <10.3.181.22-10.3.185.22 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."
CWE-79 Jun 09, 2011
CVE-2011-1953 EPSS 0.00
Post Revolution <0.8.0c-2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element.
CWE-79 Jun 06, 2011
CVE-2011-1949 EPSS 0.00
Plone <4.1 - XSS
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.
CWE-79 Jun 06, 2011
CVE-2011-1948 EPSS 0.01
Plone <4.1 - XSS
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Jun 06, 2011
CVE-2011-0767 EPSS 0.02
Imperva Securesphere Web Application Firewall - XSS
Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall 6.2, 7.x, and 8.x allows remote attackers to inject arbitrary web script or HTML via an HTTP request to a firewalled server, aka Bug ID 31759.
CWE-79 Jun 06, 2011
CVE-2011-1077 EPSS 0.04
Apache Archiva - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 02, 2011
CVE-2011-1937 EPSS 0.01
Webmin <1.540 - XSS
Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.
CWE-79 May 31, 2011
CVE-2011-2172 EPSS 0.00
IBM WebSphere Portal 7.0.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 26, 2011