CVE & Exploit Intelligence Database

Updated 33m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,780 CVEs tracked 53,326 with exploits 4,737 exploited in wild 1,544 CISA KEV 3,939 Nuclei templates 49,027 vendors 42,690 researchers
42,505 results Clear all
CVE-2010-3871 EPSS 0.00
Mahara < 1.3.2 - XSS
Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 09, 2010
CVE-2010-3077 1 PoC Analysis EPSS 0.01
Horde Application Framework <3.3.9 - XSS
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
CWE-79 Nov 09, 2010
CVE-2010-2636 EPSS 0.00
IBM WebSphere Commerce <7.0.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Nov 09, 2010
CVE-2010-0784 EPSS 0.00
IBM WAS <7.0.0.13 - XSS
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 09, 2010
CVE-2010-0783 EPSS 0.00
IBM WAS <7.0.0.13 - XSS
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 09, 2010
CVE-2010-4209 EPSS 0.03
Yahoo Yui - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
CWE-79 Nov 07, 2010
CVE-2010-4208 EPSS 0.03
Yahoo Yui - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.
CWE-79 Nov 07, 2010
CVE-2010-4207 EPSS 0.03
Yahoo Yui - XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.
CWE-79 Nov 07, 2010
CVE-2010-2477 EPSS 0.01
Paste < 1.7.3.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
CWE-79 Nov 06, 2010
CVE-2010-4183 EPSS 0.00
Htmlpurifier < 4.0.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479.
CWE-79 Nov 05, 2010
CVE-2010-4155 EPSS 0.00
Exv2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.
CWE-79 Nov 03, 2010
CVE-2010-3977 1 PoC Analysis EPSS 0.01
Deliciousdays Cforms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
CWE-79 Nov 03, 2010
CVE-2010-4101 EPSS 0.01
HP Insight Recovery < 6.1 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Recovery before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 02, 2010
CVE-2010-4030 EPSS 0.01
HP Insight Control Performance Management < 6.1 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 02, 2010
CVE-2010-4146 EPSS 0.00
Attachmate Reflection For The Web < 9.6 - XSS
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 02, 2010
CVE-2010-4120 11 PoCs Analysis EPSS 0.07
IBM Tivoli Access Manager For E-business - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.
CWE-79 Oct 28, 2010
CVE-2010-4023 EPSS 0.01
HP Insight Control Power Management < 6.1.2 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 28, 2010
CVE-2010-3994 EPSS 0.01
HP < 6.1.2 - XSS
Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 28, 2010
CVE-2010-3991 EPSS 0.01
HP Insight Control Server Migration < 6.1.2 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 28, 2010
CVE-2010-3987 EPSS 0.01
HP Insight Control Virtual Machine Management < 6.1.2 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 28, 2010