CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
42,498 results Clear all
CVE-2010-1996 EPSS 0.00
Tomatocms < 2.0.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with a /admin/category/add PATH_INFO, and the (3) keyword parameter in conjunction with a /admin/tag/add PATH_INFO.
CWE-79 May 20, 2010
CVE-2010-1995 EPSS 0.00
Tomatocms < 2.0.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new article" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.
CWE-79 May 20, 2010
CVE-2010-1985 EPSS 0.01
Sixapart Movable Type - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in Six Apart Movable Type 5.0 and 5.01 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 May 19, 2010
CVE-2010-1629 EPSS 0.00
Phorum < 5.2.14 - XSS
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.15 allows remote attackers to inject arbitrary web script or HTML via an invalid email address.
CWE-79 May 19, 2010
CVE-2010-1984 EPSS 0.00
Michael Nichols Taxonomy Breadcrumb - XSS
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonomy term name in a Breadcrumb display.
CWE-79 May 19, 2010
CVE-2010-1976 EPSS 0.00
Michael Nichols Taxonomy Breadcrumb - XSS
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.
CWE-79 May 19, 2010
CVE-2010-1584 EPSS 0.00
Drupal <6.x-2.0-rc4 - XSS
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
CWE-79 May 19, 2010
CVE-2010-1557 EPSS 0.00
HP Insight Control Server Migration <6.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP Insight Control Server Migration before 6.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 14, 2010
CVE-2010-0475 1 PoC Analysis EPSS 0.00
Palo Alto Networks Firewall < 3.0.8 - XSS
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.
CWE-79 May 14, 2010
CVE-2010-1293 EPSS 0.01
Adobe ColdFusion <9.0 - XSS
Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 13, 2010
CVE-2009-3467 EPSS 0.01
Adobe Coldfusion < 9.0 - XSS
Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 May 13, 2010
CVE-2010-1482 EPSS 0.00
CMSMS <1.7.1 - XSS
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.
CWE-79 May 12, 2010
CVE-2010-1905 1 PoC Analysis EPSS 0.03
Consona Live Assistance - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.
CWE-79 May 12, 2010
CVE-2010-1481 EPSS 0.00
PmWiki 2.2.15 - XSS
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.
CWE-79 May 12, 2010
CVE-2010-1872 2 PoCs Analysis EPSS 0.01
Tufat Flashcard - XSS
Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.
CWE-79 May 12, 2010
CVE-2009-4869 1 PoC Analysis EPSS 0.00
Hitronsoft Nasim Guest Book - XSS
Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 May 11, 2010
CVE-2009-4868 1 PoC Analysis EPSS 0.00
Hitronsoft Answer ME - XSS
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.
CWE-79 May 11, 2010
CVE-2009-4866 EPSS 0.00
Matt Wright Simple Search - XSS
Cross-site scripting (XSS) vulnerability in search.cgi in Matt's Script Archive (MSA) Simple Search 1.0 allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: some of these details are obtained from third party information.
CWE-79 May 11, 2010
CVE-2009-4864 1 PoC Analysis EPSS 0.00
I-escorts Agency Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.
CWE-79 May 11, 2010
CVE-2009-4861 EPSS 0.00
Supportpro Supportdesk - XSS
Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO SupportDesk 3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 May 11, 2010