CVE & Exploit Intelligence Database

Updated 33m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,780 CVEs tracked 53,326 with exploits 4,737 exploited in wild 1,544 CISA KEV 3,939 Nuclei templates 49,027 vendors 42,690 researchers
42,505 results Clear all
CVE-2010-4405 EPSS 0.00
Anything-digital Sh404sef < 2.1.7.761 - XSS
Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 06, 2010
CVE-2010-4402 EPSS 0.00
Devbits Register-plus < 3.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9) pass2 parameters in a register action.
CWE-79 Dec 06, 2010
CVE-2010-4329 EPSS 0.01
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.
CWE-79 Dec 02, 2010
CVE-2010-3266 2 PoCs Analysis EPSS 0.01
BugTracker.NET <3.4.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 02, 2010
CVE-2010-4366 1 PoC Analysis EPSS 0.00
Abk-soft Chameleon Social Networking - XSS
Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message.
CWE-79 Dec 01, 2010
CVE-2010-4364 EPSS 0.00
Dadabik - XSS
DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does not include the htmLawed library, which allows remote attackers to bypass the protection mechanism for CVE-2010-4355 and conduct cross-site scripting (XSS) attacks via the (1) html content and (2) rich_editor fields. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 01, 2010
CVE-2010-4361 EPSS 0.00
Jurpopage - XSS
Cross-site scripting (XSS) vulnerability in url-gateway.php in Jurpopage 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Dec 01, 2010
CVE-2010-4358 EPSS 0.00
Mrcgiguy Guestbook - XSS
Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) website, and (4) message parameters.
CWE-79 Dec 01, 2010
CVE-2010-4355 EPSS 0.00
Dadabik < 4.3 - XSS
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.
CWE-79 Dec 01, 2010
CVE-2010-4172 1 PoC Analysis EPSS 0.12
Apache Tomcat < 7.0.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
CWE-79 Nov 26, 2010
CVE-2010-3911 EPSS 0.00
Vtiger Crm < 5.2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) the password field in a Users Login action to index.php, or (3) the label parameter in a Settings GetFieldInfo action to index.php, related to modules/Settings/GetFieldInfo.php.
CWE-79 Nov 26, 2010
CVE-2008-7266 EPSS 0.00
RSA Adaptive Auth 2.x-5.7.x - XSS
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Nov 26, 2010
CVE-2010-3797 EPSS 0.00
Apple Mac OS X Server - XSS
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 16, 2010
CVE-2009-5017 EPSS 0.00
Mozilla Firefox < 3.6 - XSS
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
CWE-79 Nov 12, 2010
CVE-2010-3890 EPSS 0.00
IBM Omnifind < 9.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do.
CWE-79 Nov 12, 2010
CVE-2010-3936 EPSS 0.42
Microsoft Forefront Unified Access Gateway - XSS
Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
CWE-79 Nov 10, 2010
CVE-2010-2734 EPSS 0.48
Microsoft Forefront UAG <2010.2 - XSS
Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
CWE-79 Nov 10, 2010
CVE-2010-2733 EPSS 0.48
Microsoft Forefront UAG <2010.2 - XSS
Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
CWE-79 Nov 10, 2010
CVE-2010-4220 EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
CWE-79 Nov 09, 2010
CVE-2010-4219 EPSS 0.00
IBM Websphere Portal - XSS
Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 09, 2010