CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,780 CVEs tracked 53,326 with exploits 4,737 exploited in wild 1,544 CISA KEV 3,939 Nuclei templates 49,027 vendors 42,690 researchers
42,509 results Clear all
CVE-2011-0439 EPSS 0.00
Mahara - XSS
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.
CWE-79 Mar 28, 2011
CVE-2010-4772 1 PoC Analysis EPSS 0.00
S-CMS 2.5 - XSS
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.
CWE-79 Mar 23, 2011
CVE-2011-1414 EPSS 0.01
TIBCO tibbr <1.5.0 - XSS
Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 22, 2011
CVE-2010-4762 EPSS 0.00
OTRS <3.0.0-beta2 - XSS
Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.
CWE-79 Mar 18, 2011
CVE-2008-7275 EPSS 0.00
OTRS <2.3.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.
CWE-79 Mar 18, 2011
CVE-2011-1427 2 PoCs Analysis EPSS 0.01
Kodak InSite 5.5.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp.
CWE-79 Mar 15, 2011
CVE-2011-0457 EPSS 0.00
E107 < 0.7.22 - XSS
Cross-site scripting (XSS) vulnerability in e107 0.7.22 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 15, 2011
CVE-2010-4757 EPSS 0.00
e107 <0.7.23 - XSS
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.
CWE-79 Mar 15, 2011
CVE-2011-0700 EPSS 0.01
Wordpress < 3.0.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
CWE-79 Mar 14, 2011
CVE-2011-0280 EPSS 0.01
HP Power Manager < 4.3.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 14, 2011
CVE-2011-0169 EPSS 0.00
Apple Safari <5.0.4 - XSS
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
CWE-79 Mar 11, 2011
CVE-2011-1308 EPSS 0.00
IBM Websphere Application Server < 7.0.0.13 - XSS
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 08, 2011
CVE-2011-0455 EPSS 0.00
Thingslabo Things Bbs < 2.0.2 - XSS
Cross-site scripting (XSS) vulnerability in Things BBS before 2.0.3 and BBS Thread before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 03, 2011
CVE-2011-1106 1 PoC Analysis EPSS 0.01
IBM Lotus Sametime - XSS
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.
CWE-79 Mar 01, 2011
CVE-2010-4753 EPSS 0.00
LightNEasy 3.2.1 - XSS
Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a forced SQL error message.
CWE-79 Mar 01, 2011
CVE-2010-4749 1 PoC Analysis EPSS 0.07
BLOG:CMS 4.2.1.e - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.
CWE-79 Mar 01, 2011
CVE-2010-4748 EPSS 0.00
PmWiki 2.2.20 - XSS
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 01, 2011
CVE-2010-4747 1 PoC Analysis EPSS 0.01
WordPress Processing Embed <0.5 - XSS
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.
CWE-79 Mar 01, 2011
CVE-2011-1105 EPSS 0.01
Mutare Evm - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mutare EVM allow remote attackers to inject arbitrary web script or HTML via (1) a delivery address and possibly (2) a PIN.
CWE-79 Feb 28, 2011
CVE-2011-1102 EPSS 0.00
F-secure Policy Manager - XSS
Cross-site scripting (XSS) vulnerability in the WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 25, 2011