CVE & Exploit Intelligence Database

Updated 19m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
42,501 results Clear all
CVE-2010-2613 1 PoC Analysis EPSS 0.02
Harmistechnology Com Awd Song - XSS
Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to index.php.
CWE-79 Jul 02, 2010
CVE-2010-1520 EPSS 0.00
TaskFreak! <0.6.4 - XSS
Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.
CWE-79 Jun 30, 2010
CVE-2009-4910 EPSS 0.00
Cisco Asa 5580 < 8.1\(1\) - XSS
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.
CWE-79 Jun 29, 2010
CVE-2010-2514 EPSS 0.00
Dacian Strain Com Jfaq - XSS
Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add2 action to index.php.
CWE-79 Jun 28, 2010
CVE-2010-2509 1 PoC Analysis EPSS 0.00
2daybiz Web Template Software - XSS
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.
CWE-79 Jun 28, 2010
CVE-2010-2506 EXPLOITED EPSS 0.00
Cisco Linksys Firmware - XSS
Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter.
CWE-79 Jun 28, 2010
CVE-2010-2503 EPSS 0.00
Splunk - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067; (2) unspecified "user->user or user->admin" vectors, aka SPL-31084; or (3) unspecified "user input," aka SPL-31085.
CWE-79 Jun 28, 2010
CVE-2010-2230 EPSS 0.00
Moodle < 1.8.12 - XSS
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
CWE-79 Jun 28, 2010
CVE-2010-2229 EPSS 0.01
Moodle < 1.8.12 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Jun 28, 2010
CVE-2010-2228 EPSS 0.01
Moodle < 1.8.12 - XSS
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
CWE-79 Jun 28, 2010
CVE-2010-2464 1 PoC Analysis EPSS 0.04
Rsjoomla Com Rscomments - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
CWE-79 Jun 25, 2010
CVE-2010-2463 1 PoC Analysis EPSS 0.00
Jamroom < 4.1.8 - XSS
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
CWE-79 Jun 25, 2010
CVE-2010-2458 1 PoC Analysis EPSS 0.04
2daybiz Video Community Portal Script - XSS
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.
CWE-79 Jun 25, 2010
CVE-2010-2457 1 PoC Analysis EPSS 0.00
Qsoft-inc K-search - XSS
Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.
CWE-79 Jun 25, 2010
CVE-2009-4908 1 PoC Analysis EPSS 0.03
Dootzky Oblog - XSS
Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (5) article_id or (6) title parameter to admin/write.php, the (7) category_id or (8) category_name parameter to admin/groups.php, the (9) blogroll_id or (10) title parameter to admin/blogroll.php, or the (11) blog_name or (12) tag_line parameter to admin/settings.php.
CWE-79 Jun 25, 2010
CVE-2009-4903 EPSS 0.00
Dootzky Oblog - XSS
Cross-site scripting (XSS) vulnerability in index.php in oBlog allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jun 25, 2010
CVE-2010-2437 1 PoC Analysis EPSS 0.00
Anecms Blog < 1.3 - XSS
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.
CWE-79 Jun 24, 2010
CVE-2010-0779 EPSS 0.00
IBM WebSphere Application Server <6.0.2.43-7.0.0.11 - XSS
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 24, 2010
CVE-2010-0778 EPSS 0.00
IBM WAS <7.0.0.11 - XSS
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 24, 2010
CVE-2010-1625 EPSS 0.00
Malcom BOX Lxr Cross Referencer < 0.9.6 - XSS
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448.
CWE-79 Jun 24, 2010