CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
42,498 results Clear all
CVE-2009-4859 EPSS 0.00
Onlinetechtools.com Owos Lite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Online Work Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) default.asp and (2) report.asp, and the (3) go parameter to login.asp.
CWE-79 May 11, 2010
CVE-2009-4858 1 PoC Analysis EPSS 0.00
Turnkeyforms Yahoo-answers-clone - XSS
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
CWE-79 May 11, 2010
CVE-2009-4857 1 PoC Analysis EPSS 0.01
Ecomstudio Php Photo Vote1.3f - XSS
Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 May 11, 2010
CVE-2009-4856 1 PoC Analysis EPSS 0.01
Ecomstudio Php Easy Shopping Cart - XSS
Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter.
CWE-79 May 11, 2010
CVE-2010-1856 1 PoC Analysis EPSS 0.01
Realitymedias Repairshop2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.
CWE-79 May 07, 2010
CVE-2010-1854 EPSS 0.00
Phpscripte24 Pay Per Watch & Bid Auktions System - XSS
Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might be resultant from CVE-2010-1855.
CWE-79 May 07, 2010
CVE-2009-4853 EPSS 0.00
Jumpbox < 1.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 07, 2010
CVE-2009-4852 EPSS 0.00
Festic Semanticscuttle < 0.94 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SemanticScuttle before 0.94.1 allow remote attackers to inject arbitrary web script or HTML via the sort parameter to index.php, and other unspecified vectors, a different issue than CVE-2008-6113. NOTE: some of these details are obtained from third party information.
CWE-79 May 07, 2010
CVE-2009-4848 EPSS 0.00
Toutvirtual Virtualiq - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId parameter to tvserver/server/user/setPermissions.jsp, (2) deptName parameter to tvserver/server/user/addDepartment.jsp, (3) ID parameter to tvserver/server/inventory/inventoryTabs.jsp, (4) reportName parameter to tvserver/reports/virtualIQAdminReports.do, or (5) middleName parameter in a save action to tvserver/user/user.do.
CWE-79 May 07, 2010
CVE-2010-1453 1 PoC Analysis EPSS 0.02
Piwik <0.5.5 - XSS
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.
CWE-79 May 07, 2010
CVE-2010-1143 2 PoCs Analysis EPSS 0.01
VMware View <3.1.3 - XSS
Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 07, 2010
CVE-2009-4842 EPSS 0.00
Toutvirtual Virtualiq - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) addNewDept, (2) deptId, or (3) deptDesc parameter to tvserver/server/user/addDepartment.jsp; or the (4) firstName, (5) lastName, or (6) email parameter in a save action to tvserver/user/user.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 May 07, 2010
CVE-2010-1746 1 PoC Analysis EPSS 0.00
Toolsjx Com Grid - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php.
CWE-79 May 06, 2010
CVE-2010-1742 1 PoC Analysis EPSS 0.04
Satyadeep Scratcher - XSS
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.
CWE-79 May 06, 2010
CVE-2010-1724 2 PoCs Analysis EPSS 0.03
Zikula Application Framework - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.
CWE-79 May 06, 2010
CVE-2009-4839 EPSS 0.00
Secureideas Basic Analysis And Security Engine < 1.4.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) admin/base_useradmin.php, (3) base_conf_contents.php, (4) base_qry_sqlcalls.php, and (5) base_ag_main.php.
CWE-79 May 06, 2010
CVE-2009-4837 EPSS 0.00
Secureideas Basic Analysis And Security Engine < 1.4.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[1] parameter to base/base_qry_main.php, or the time[0][1] parameter to (2) base/base_stat_alerts.php or (3) base/base_stat_uaddr.php. NOTE: some of these details are obtained from third party information.
CWE-79 May 06, 2010
CVE-2010-1712 1 PoC Analysis EPSS 0.01
Webmobo Wbnews - XSS
Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. NOTE: some of these details are obtained from third party information.
CWE-79 May 04, 2010
CVE-2010-1711 1 PoC Analysis EPSS 0.04
Ramoncastro Siestta - XSS
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.
CWE-79 May 04, 2010
CVE-2010-1709 EPSS 0.00
G5-scripts Auto-img-gallery - XSS
Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pass parameters.
CWE-79 May 04, 2010