CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
42,501 results Clear all
CVE-2010-3427 EPSS 0.00
Open Classifieds 1.7.0.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php.
CWE-79 Sep 16, 2010
CVE-2010-3425 1 PoC Analysis EPSS 0.03
SmarterStats <5.3.3819 - XSS
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Sep 16, 2010
CVE-2010-3424 EPSS 0.00
Invision Power Board <3.1.2 - XSS
Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 16, 2010
CVE-2010-3421 EPSS 0.00
ProductCart 3, 4.1 SP1 - XSS
Cross-site scripting (XSS) vulnerability in AffiliateLogin.asp in ProductCart 3, 4.1 SP1, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter, a different vector than CVE-2004-2174 and CVE-2005-0995. NOTE: some of these details are obtained from third party information.
CWE-79 Sep 16, 2010
CVE-2010-3420 EPSS 0.00
PowerStore 3.0 - XSS
Cross-site scripting (XSS) vulnerability in Products_Results.php in PowerStore 3.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_WADAProducts parameter.
CWE-79 Sep 16, 2010
CVE-2010-3418 EPSS 0.00
NetArt Media Car Portal <2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) car_id parameter to index.php and (2) y parameter to include/images.php.
CWE-79 Sep 16, 2010
CVE-2010-3089 EPSS 0.00
GNU Mailman <2.1.14rc1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
CWE-79 Sep 15, 2010
CVE-2010-3010 EPSS 0.00
HP 3Com OfficeConnect Gigabit VPN Firewall <1.0.13 - XSS
Cross-site scripting (XSS) vulnerability on the HP 3Com OfficeConnect Gigabit VPN Firewall 3CREVF100-73 with firmware before 1.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: a separate XSS issue for HP System Management Homepage (SMH) was originally assigned CVE-2010-3010 due to a CNA error, but CVE-2010-3012 is the appropriate identifier for the SMH issue.
CWE-79 Sep 15, 2010
CVE-2010-3082 EPSS 0.00
Django <1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.
CWE-79 Sep 14, 2010
CVE-2010-0152 EPSS 0.00
IBM Proventia Network Mail Security System Virtual Appliance - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the userfilter parameter to pvm_user_management.php, (3) the ping parameter to sys_tools.php in a sys_ping.php action, (4) the action parameter to pvm_cert_commaction.php, (5) the action parameter to pvm_cert_serveraction.php, (6) the action parameter to pvm_smtpstore.php, (7) the l parameter to sla/index.php, or (8) unspecified stored data; and allow remote authenticated users to inject arbitrary web script or HTML via (9) saved search filters.
CWE-79 Sep 14, 2010
CVE-2010-3317 EPSS 0.00
IBM Records Manager <4.5.1.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 13, 2010
CVE-2010-3202 1 PoC Analysis EPSS 0.02
Flock Browser 3.0.0.3989 - XSS
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.
CWE-79 Sep 13, 2010
CVE-2010-2366 EPSS 0.00
Futomi Access Analyzer Cgi < 4.0.2 - XSS
Cross-site scripting (XSS) vulnerability in futomi CGI Cafe Access Analyzer CGI Professional, and Standard 4.0.2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 13, 2010
CVE-2010-3263 EPSS 0.00
phpMyAdmin <3.3.7 - XSS
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.
CWE-79 Sep 10, 2010
CVE-2010-3003 5 PoCs Analysis EPSS 0.00
HP Insight Diagnostics Online Edition <8.5.0-11 - XSS
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 10, 2010
CVE-2010-2957 EPSS 0.00
Serendipity <1.5.4 - XSS
Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 10, 2010
CVE-2010-2769 EPSS 0.01
Mozilla Firefox < 2.0.6 - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
CWE-79 Sep 09, 2010
CVE-2010-2768 EPSS 0.01
Mozilla Firefox <3.5.12 & <3.6.9 - XSS
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
CWE-79 Sep 09, 2010
CVE-2010-2763 EPSS 0.01
Mozilla Firefox <3.5.12, Thunderbird <3.0.7, SeaMonkey <2.0.7 - XSS
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
CWE-79 Sep 09, 2010
CVE-2010-2958 EPSS 0.00
phpMyAdmin <3.3.6 - XSS
Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.
CWE-79 Sep 08, 2010