CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
42,498 results Clear all
CVE-2010-1515 EPSS 0.00
TomatoCMS 2.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword parameter in conjunction with a /admin/multimedia/set/list PATH_INFO; the (4) keyword or (5) fileId parameter in conjunction with a /admin/multimedia/file/list PATH_INFO; or the (6) name, (7) email, or (8) address parameter in conjunction with a /admin/ad/client/list PATH_INFO.
CWE-79 Jun 15, 2010
CVE-2010-2292 EPSS 0.00
D-link Di-604 - XSS
Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP field.
CWE-79 Jun 15, 2010
CVE-2010-2290 EPSS 0.01
Mcafee Unified Threat Management Firewall Firmware - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/help in McAfee Unified Threat Management (UTM) Firewall (formerly SnapGear) firmware 3.0.0 through 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Jun 15, 2010
CVE-2010-2288 EPSS 0.00
Juniper Secure Access - XSS
Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to inject arbitrary web script or HTML via the DSSignInURL cookie.
CWE-79 Jun 15, 2010
CVE-2009-4894 EPSS 0.00
Punbb < 1.3.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in PunBB before 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) password or (2) e-mail.
CWE-79 Jun 15, 2010
CVE-2010-2265 1 PoC Analysis EPSS 0.25
Microsoft Windows 2003 Server - XSS
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
CWE-79 Jun 15, 2010
CVE-2010-1762 EPSS 0.01
Apple Safari < 4.0.5 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML in a TEXTAREA element.
CWE-79 Jun 11, 2010
CVE-2010-1418 EPSS 0.01
Apple Safari <5.0 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via a FRAME element with a SRC attribute composed of a javascript: sequence preceded by spaces.
CWE-79 Jun 11, 2010
CVE-2010-0544 EPSS 0.01
Apple Safari < 4.0.5 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to a malformed URL.
CWE-79 Jun 11, 2010
CVE-2010-1395 EPSS 0.01
Apple Safari <5.0 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving DOM constructor objects, related to a "scope management issue."
CWE-79 Jun 11, 2010
CVE-2010-1394 EPSS 0.01
Apple Safari <5.0 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document fragments.
CWE-79 Jun 11, 2010
CVE-2010-1390 EPSS 0.01
Apple Safari <5.0 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.
CWE-79 Jun 11, 2010
CVE-2010-1389 EPSS 0.01
Apple Safari <5.0 - XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) paste or (2) drag-and-drop operation for a selection.
CWE-79 Jun 11, 2010
CVE-2009-4890 EPSS 0.00
Retrieve Vbook - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the login application in vBook 4.2.17 allow remote attackers to inject arbitrary web script or HTML via the (1) title and (2) message parameters.
CWE-79 Jun 11, 2010
CVE-2009-4888 1 PoC Analysis EPSS 0.04
Nskate Phortail - XSS
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) ti, and (4) txt parameters.
CWE-79 Jun 11, 2010
CVE-2009-4885 1 PoC Analysis EPSS 0.00
Bernhard Frohlich Phpcom - XSS
Cross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CWE-79 Jun 11, 2010
CVE-2010-2260 EPSS 0.00
Gambitdesign Bandwidth Meter - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Gambit Design Bandwidth Meter, 0.72 and possibly 1.2, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) view_by_name.php or (2) view_by_ip.php in admin/. NOTE: some sources report that the affected product is ShaPlus Bandwidth Meter, but this is incorrect.
CWE-79 Jun 09, 2010
CVE-2010-2258 EPSS 0.00
Phpbannerexchange - XSS
Cross-site scripting (XSS) vulnerability in signupconfirm.php in phpBannerExchange 1.2 Arabic allows remote attackers to inject arbitrary web script or HTML via the bannerurl parameter.
CWE-79 Jun 09, 2010
CVE-2010-2256 1 PoC Analysis EPSS 0.01
Payperviewvideosoftware Pay Per Minute Video Chat Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.
CWE-79 Jun 09, 2010
CVE-2010-1257 EPSS 0.37
Microsoft Office InfoPath <2007 SP2 - XSS
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.
CWE-79 Jun 08, 2010