CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,780 CVEs tracked 53,326 with exploits 4,737 exploited in wild 1,544 CISA KEV 3,939 Nuclei templates 49,027 vendors 42,690 researchers
42,505 results Clear all
CVE-2011-0641 EPSS 0.00
Heart5 Statpresscn - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 25, 2011
CVE-2011-0274 EPSS 0.01
HP Business Availability Center - XSS
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 24, 2011
CVE-2011-0509 EPSS 0.01
Vaadin < 6.4.8 - XSS
Cross-site scripting (XSS) vulnerability in Vaadin before 6.4.9 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the index page.
CWE-79 Jan 20, 2011
CVE-2011-0508 EPSS 0.00
Contao Cms - XSS
Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
CWE-79 Jan 20, 2011
CVE-2011-0504 1 PoC Analysis EPSS 0.02
Vamshop Vam Shop - XSS
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php, (2) search parameter to admin/customers.php, or (3) STORE_NAME parameter to admin/configuration.php.
CWE-79 Jan 20, 2011
CVE-2010-4331 1 PoC Analysis EPSS 0.01
Seopanel - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default_news or (2) sponsors cookies, which are not properly handled by (a) controllers/index.ctrl.php or (b) controllers/settings.ctrl.php.
CWE-79 Jan 20, 2011
CVE-2010-4071 EPSS 0.00
Otrs - XSS
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.
CWE-79 Jan 20, 2011
CVE-2010-3931 EPSS 0.01
Rocomotion P Board < 1.18 - XSS
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Jan 20, 2011
CVE-2011-0486 EPSS 0.00
IBM Cognos 8 Business Intelligence - XSS
Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.
CWE-79 Jan 18, 2011
CVE-2010-4646 EPSS 0.00
Hastymail2 < 1.0 - XSS
Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01 allows remote attackers to inject arbitrary web script or HTML via a crafted background attribute within a cell in a TABLE element, related to improper use of the htmLawed filter.
CWE-79 Jan 18, 2011
CVE-2010-4339 EPSS 0.00
Hypermail - XSS
Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted From address, which is not properly handled when indexing messages.
CWE-79 Jan 14, 2011
CVE-2010-4647 2 PoCs Analysis EPSS 0.10
Eclipse Ide < 3.6.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.
CWE-79 Jan 13, 2011
CVE-2008-7271 2 PoCs Analysis EPSS 0.00
Eclipse IDE - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.
CWE-79 Jan 13, 2011
CVE-2011-0315 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
CWE-79 Jan 12, 2011
CVE-2010-3926 EPSS 0.00
Wb-i Sgx-sp Final < 10.00 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Shop.cgi in SGX-SP Final before 11.00 and SGX-SP Final NE before 11.00 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 12, 2011
CVE-2011-0005 1 PoC Analysis EPSS 0.00
Joomla! <1.0.16 - XSS
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.
CWE-79 Jan 11, 2011
CVE-2010-4693 2 PoCs Analysis EPSS 0.00
Coppermine Photo Gallery <1.5.10 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.
CWE-79 Jan 11, 2011
CVE-2011-0004 EPSS 0.01
Piwik <1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 10, 2011
CVE-2010-4322 EPSS 0.00
Novell Vibe Onprem - XSS
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.
CWE-79 Jan 07, 2011
CVE-2010-3201 1 PoC Analysis EPSS 0.02
NetWin Surgemail <4.3g - XSS
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
CWE-79 Jan 07, 2011