CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,640 CVEs tracked 53,321 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,006 vendors 42,664 researchers
42,493 results Clear all
CVE-2010-1619 EPSS 0.00
Moodle < 1.8.12 - XSS
Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML entities.
CWE-79 Apr 29, 2010
CVE-2010-1618 EPSS 0.00
Ja-sig Phpcas Client Library < 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.
CWE-79 Apr 29, 2010
CVE-2010-1614 EPSS 0.00
Moodle < 1.8.12 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.
CWE-79 Apr 29, 2010
CVE-2010-0817 EXPLOITED 1 PoC Analysis EPSS 0.55
Microsoft SharePoint Server 2007 <12.0.0.6421 - XSS
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
CWE-79 Apr 29, 2010
CVE-2010-1609 EPSS 0.00
SAP Netweaver - XSS
Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 29, 2010
CVE-2010-1606 1 PoC Analysis EPSS 0.01
Ncrypted Nct Jobs Portal Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.
CWE-79 Apr 29, 2010
CVE-2010-1594 EPSS 0.00
OCS Inventory NG 1.02.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Apr 28, 2010
CVE-2010-1593 EPSS 0.01
SilverStripe <2.3.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
CWE-79 Apr 28, 2010
CVE-2010-1590 EPSS 0.00
Rocksalt International VP-ASP Shopping Cart <6.50 - XSS
Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.
CWE-79 Apr 28, 2010
CVE-2010-1036 EPSS 0.01
HP System Insight Manager <6.0 - XSS
Cross-site scripting (XSS) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2010
CVE-2009-4829 EPSS 0.00
James Glasgow Autologout - XSS
Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users with administer autologout privileges to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 27, 2010
CVE-2009-4823 1 PoC Analysis EPSS 0.01
Cpanel - XSS
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.
CWE-79 Apr 27, 2010
CVE-2009-4822 2 PoCs Analysis EPSS 0.00
Kasseler-cms Kasseler Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
CWE-79 Apr 27, 2010
CVE-2009-4814 1 PoC Analysis EPSS 0.02
Wolfram Webmathematica - XSS
Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.
CWE-79 Apr 27, 2010
CVE-2009-4813 1 PoC Analysis EPSS 0.02
Mybb - XSS
Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.
CWE-79 Apr 27, 2010
CVE-2010-1543 EPSS 0.00
Drupal eTracker <6.x-1.2 - XSS
Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.
CWE-79 Apr 26, 2010
CVE-2010-1541 EPSS 0.00
DFD Cart <1.198-1.197 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.
CWE-79 Apr 26, 2010
CVE-2010-1539 EPSS 0.00
Drupal Workflow <6.1.4 - XSS
Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comment field.
CWE-79 Apr 26, 2010
CVE-2010-1536 EPSS 0.00
Drupal <5.x-2.2, <6.x-2.9 - XSS
Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthis privileges, to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 26, 2010
CVE-2010-1530 EPSS 0.00
Drupal 6.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.
CWE-79 Apr 26, 2010