CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
42,501 results Clear all
CVE-2010-3294 EPSS 0.00
APC <3.1.4 - XSS
Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 24, 2010
CVE-2010-2491 EPSS 0.01
Roundup < 1.4.13 - XSS
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
CWE-79 Sep 24, 2010
CVE-2010-3489 1 PoC Analysis EPSS 0.02
CMS Digital Workroom <5.5.0 - XSS
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the goback parameter.
CWE-79 Sep 22, 2010
CVE-2010-3314 1 PoC Analysis EPSS 0.02
EGroupware <1.6.003 - XSS
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CWE-79 Sep 22, 2010
CVE-2010-3094 EPSS 0.00
Drupal 6.x <6.18 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.
CWE-79 Sep 21, 2010
CVE-2010-3472 EPSS 0.00
IBM FileNet P8 AE <3.5.1.21 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2010
CVE-2010-3470 EPSS 0.00
IBM FileNet P8 Application Engine <4.0.2.7-P8AE-FP007 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 and 4.0.2.x before 4.0.2.7-P8AE-FP007 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2010
CVE-2009-5000 EPSS 0.00
IBM Filenet P8 Application Engine - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.3-P8AE-FP003 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to .jsp pages.
CWE-79 Sep 20, 2010
CVE-2009-4999 EPSS 0.00
IBM Filenet P8 Application Engine - XSS
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script or HTML via the Name field.
CWE-79 Sep 20, 2010
CVE-2010-3262 EPSS 0.00
Flock Browser <3.0.0.4114 - XSS
Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
CWE-79 Sep 20, 2010
CVE-2010-2080 EPSS 0.00
Otrs - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 20, 2010
CVE-2010-3466 EPSS 0.00
NetArt Media iBoutique.MALL 1.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 17, 2010
CVE-2010-3465 EPSS 0.00
XSE Shopping Cart <1.5.3.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
CWE-79 Sep 17, 2010
CVE-2010-3463 EPSS 0.00
SantaFox 2.02 - XSS
Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.
CWE-79 Sep 17, 2010
CVE-2010-3462 1 PoC Analysis EPSS 0.01
Mollify <1.6-1.6.5.5 - XSS
Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the confirm parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 17, 2010
CVE-2010-3459 EPSS 0.01
AXIGEN Mail Server <7.4.2 - XSS
Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 17, 2010
CVE-2010-3457 1 PoC Analysis EPSS 0.02
Symphony CMS <2.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-default-theme/ or (2) send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 17, 2010
CVE-2010-3455 EPSS 0.00
AChecker 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0 allows remote attackers to inject arbitrary web script or HTML via the uri parameter.
CWE-79 Sep 17, 2010
CVE-2010-3012 EPSS 0.01
HP SMH <6.2 - XSS
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue was originally assigned CVE-2010-3010 due to a CNA error.
CWE-79 Sep 17, 2010
CVE-2010-3324 1 PoC Analysis EPSS 0.26
Microsoft Internet Explorer 8 - Auth Bypass
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
CWE-79 Sep 17, 2010