CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,780 CVEs tracked 53,326 with exploits 4,737 exploited in wild 1,544 CISA KEV 3,939 Nuclei templates 49,027 vendors 42,690 researchers
42,505 results Clear all
CVE-2010-4497 EPSS 0.01
Tibco Activecatalog < 1.0 - XSS
Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 07, 2011
CVE-2010-4324 EPSS 0.02
Novell Identity Manager < 3.7.0 - XSS
Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 07, 2011
CVE-2010-4536 EPSS 0.04
Wordpress < 3.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
CWE-79 Jan 03, 2011
CVE-2010-4524 EPSS 0.01
Mhonarc - XSS
Cross-site scripting (XSS) vulnerability in lib/mhtxthtml.pl in MHonArc 2.6.16 allows remote attackers to inject arbitrary web script or HTML via a malformed start tag and end tag for a SCRIPT element, as demonstrated by <scr<body>ipt> and </scr<body>ipt> sequences.
CWE-79 Jan 03, 2011
CVE-2010-4348 1 PoC Analysis EPSS 0.11
Mantisbt < 1.2.3 - XSS
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the db_type parameter, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.
CWE-79 Jan 03, 2011
CVE-2010-4642 EPSS 0.00
Xwiki < 2.4 - XSS
Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 30, 2010
CVE-2010-4640 EPSS 0.00
Xwiki Watch - XSS
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0 allow remote attackers to inject arbitrary web script or HTML via the rev parameter to (1) bin/viewrev/Main/WebHome and (2) bin/view/Blog, and the (3) register_first_name and (4) register_last_name parameters to bin/register/XWiki/Register. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Dec 30, 2010
CVE-2010-4637 EPSS 0.00
Finalcut Feedlist - XSS
Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
CWE-79 Dec 30, 2010
CVE-2010-4631 1 PoC Analysis EPSS 0.06
Pilotcart Pilot Cart - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the specific parameter to (4) quote.asp and (5) buyitnow.
CWE-79 Dec 30, 2010
CVE-2010-4630 EPSS 0.00
Fubra Wp-survey-and-quiz-tool - XSS
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
CWE-79 Dec 30, 2010
CVE-2010-4522 EPSS 0.00
Mybb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) editpost.php, (2) member.php, and (3) newreply.php.
CWE-79 Dec 30, 2010
CVE-2010-4276 1 PoC Analysis EPSS 0.05
Livezilla - XSS
Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary web script or HTML via the livezilla parameter in a track action to server.php.
CWE-79 Dec 30, 2010
CVE-2010-4618 EPSS 0.00
Algisinfo Aicontactsafe < 2.0.13 - XSS
Cross-site scripting (XSS) vulnerability in the Algis Info aiContactSafe component before 2.0.14 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 29, 2010
CVE-2010-4616 EPSS 0.00
Impresscms < 1.2.3 - XSS
Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before 1.2.4, allows remote attackers to inject arbitrary web script or HTML via the quicksearch_ContentContent parameter.
CWE-79 Dec 29, 2010
CVE-2010-4610 1 PoC Analysis EPSS 0.01
Html-edit Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to inject arbitrary web script or HTML via the error parameter.
CWE-79 Dec 29, 2010
CVE-2010-4607 1 PoC Analysis EPSS 0.02
Habari - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) additem_form parameter to system/admin/dash_additem.php and the (2) status_data[] parameter to system/admin/dash_status.php. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 29, 2010
CVE-2010-4521 EPSS 0.00
Earl Miles Views - XSS
Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.
CWE-79 Dec 23, 2010
CVE-2010-4520 EPSS 0.00
Earl Miles Views - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.
CWE-79 Dec 23, 2010
CVE-2010-4590 EPSS 0.00
IBM Lotus Mobile Connect < 6.1.3 - XSS
Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2010
CVE-2010-4589 EPSS 0.00
IBM Enovia - XSS
Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property.
CWE-79 Dec 22, 2010