CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
42,498 results Clear all
CVE-2010-1459 EPSS 0.00
ASP.NET Mono <2.6.4 - XSS
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
CWE-79 May 27, 2010
CVE-2010-2049 EPSS 0.00
Manageengine Adaudit Plus - XSS
Cross-site scripting (XSS) vulnerability in jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0 build 4043 allows remote attackers to inject arbitrary web script or HTML via the reportList parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 May 25, 2010
CVE-2010-2048 EPSS 0.00
Menhir Heartbeat - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 25, 2010
CVE-2010-2046 EPSS 0.00
Com Activehelper Livehelp - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER parameter to server/index.php.
CWE-79 May 25, 2010
CVE-2010-2043 EPSS 0.01
Magnoware Datatrack System - XSS
Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are obtained from third party information.
CWE-79 May 25, 2010
CVE-2010-2041 EPSS 0.01
Php-calendar < 2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.
CWE-79 May 25, 2010
CVE-2010-2040 1 PoC Analysis EPSS 0.02
V-eva Shopzilla Affiliate Script Php - XSS
Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 May 25, 2010
CVE-2010-2038 1 PoC Analysis EPSS 0.00
Gpeasy Cms - XSS
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from third party information.
CWE-79 May 25, 2010
CVE-2010-2032 1 PoC Analysis EPSS 0.02
Caucho Resin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.
CWE-79 May 24, 2010
CVE-2010-2030 EPSS 0.00
Alan Palazzolo External Link Page - XSS
Cross-site scripting (XSS) vulnerability in the External Link Page module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the administration and redirect pages.
CWE-79 May 24, 2010
CVE-2010-2017 EPSS 0.00
Bukulokomedia Lokomedia Cms - XSS
Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to inject arbitrary web script or HTML via the kata parameter. NOTE: some of these details are obtained from third party information.
CWE-79 May 24, 2010
CVE-2010-2014 EPSS 0.00
Createch-group Lisk Cms - XSS
Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter.
CWE-79 May 24, 2010
CVE-2010-2013 EPSS 0.00
Createch-group Lisk Cms - XSS
Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 May 24, 2010
CVE-2010-2010 EPSS 0.00
Chaos Tool Suite Ctools - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.
CWE-79 May 21, 2010
CVE-2010-2003 1 PoC Analysis EPSS 0.08
Proxy2 Advanced Poll - XSS
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.
CWE-79 May 20, 2010
CVE-2010-2002 EPSS 0.00
Addison Berry Wordfilter - XSS
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list.
CWE-79 May 20, 2010
CVE-2010-2001 EPSS 0.00
Ninjitsuweb Civiregister - XSS
Cross-site scripting (XSS) vulnerability in the CiviRegister module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.
CWE-79 May 20, 2010
CVE-2010-2000 EPSS 0.00
RON Jerome Bibliography - XSS
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1358.
CWE-79 May 20, 2010
CVE-2010-1998 EPSS 0.00
Kevinhankens Tablefield - XSS
Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.
CWE-79 May 20, 2010
CVE-2010-1997 1 PoC Analysis EPSS 0.00
Saurus Cms - XSS
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.
CWE-79 May 20, 2010