CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
42,509 results Clear all
CVE-2011-1765 EPSS 0.00
MediaWiki <1.16.5 - XSS
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .shtml at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578 and CVE-2011-1587.
CWE-79 May 23, 2011
CVE-2011-2020 EPSS 0.01
TIBCO iProcess Engine <11.1.3 - iProcess Workspace <11.3.1 - XSS
Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 20, 2011
CVE-2011-1838 1 PoC Analysis EPSS 0.09
TWiki <5.0.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
CWE-79 May 20, 2011
CVE-2011-0962 2 PoCs Analysis EPSS 0.06
Cisco Unified Operations Manager < 8.5 - XSS
Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.
CWE-79 May 20, 2011
CVE-2011-0961 2 PoCs Analysis EPSS 0.15
Ciscoworks Common Services < 3.3 - XSS
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.
CWE-79 May 20, 2011
CVE-2011-0959 6 PoCs Analysis EPSS 0.38
Cisco Unified Operations Manager < 8.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.
CWE-79 May 20, 2011
CVE-2011-1856 EPSS 0.01
HP BAC <8.06 - XSS
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.06 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 16, 2011
CVE-2011-1899 EPSS 0.00
CA eHealth <6.2.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CA eHealth 6.0.x, 6.1.x, 6.2.1, and 6.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 May 16, 2011
CVE-2011-0613 EPSS 0.01
Adobe Robohelp - XSS
Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/WildFireExt/TemplateStock/.
CWE-79 May 16, 2011
CVE-2011-1405 EPSS 0.00
Mahara <1.3.6 - XSS
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.
CWE-79 May 13, 2011
CVE-2011-2087 EPSS 0.01
Apache Struts 2.x <2.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
CWE-79 May 13, 2011
CVE-2011-1772 1 PoC Analysis EPSS 0.59
Apache Struts 2.x <2.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
CWE-79 May 13, 2011
CVE-2011-1737 EPSS 0.01
HP Palm webOS <1.4.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 13, 2011
CVE-2011-2078 EPSS 0.00
MediaCAST <8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 10, 2011
CVE-2011-1570 EPSS 0.01
Liferay Portal CE <6.0.6 - XSS
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
CWE-79 May 07, 2011
CVE-2011-1504 EPSS 0.00
Liferay Portal CE <6.0.6 - XSS
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.
CWE-79 May 07, 2011
CVE-2011-1825 EPSS 0.00
CA Arcot WebFort VAS <6.2.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 05, 2011
CVE-2011-1423 EPSS 0.00
RSA DLP Enterprise Manager <8.5 SP1 - XSS
Cross-site scripting (XSS) vulnerability in RSA Data Loss Prevention (DLP) Enterprise Manager 8.x before 8.5 SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 05, 2011
CVE-2011-1727 EPSS 0.01
HP SiteScope <11.1 - XSS
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an "HTML injection" issue.
CWE-79 May 03, 2011
CVE-2011-1726 EPSS 0.01
HP SiteScope <11.1 - XSS
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 03, 2011