CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,640 CVEs tracked 53,321 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,006 vendors 42,664 researchers
42,493 results Clear all
CVE-2010-1091 1 PoC Analysis EPSS 0.01
phpMySite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.
CWE-79 Mar 24, 2010
CVE-2010-1080 EPSS 0.00
Pulse CMS 1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter.
CWE-79 Mar 23, 2010
CVE-2010-1079 EPSS 0.00
Sawmill <7.2.18 - XSS
Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 23, 2010
CVE-2010-1076 EPSS 0.00
Entry Level CMS - XSS
Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 23, 2010
CVE-2010-1074 EPSS 0.00
Drupal <6.x-1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging.
CWE-79 Mar 23, 2010
CVE-2010-1072 EPSS 0.00
Sniggabo CMS 2.21 - XSS
Cross-site scripting (XSS) vulnerability in search.php in Sniggabo CMS 2.21 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CWE-79 Mar 23, 2010
CVE-2010-1068 EPSS 0.00
NetWin SurgeFTP 2.3a6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
CWE-79 Mar 23, 2010
CVE-2009-4736 EPSS 0.01
CommonSense CMS 5.0 - XSS
Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CWE-79 Mar 23, 2010
CVE-2010-1052 1 PoC Analysis EPSS 0.00
AudiStat 1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 23, 2010
CVE-2010-1048 1 PoC Analysis EPSS 0.00
Uiga Business Portal - XSS
Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 23, 2010
CVE-2010-0736 EPSS 0.00
ViewVC <1.0.10, <1.1.4 - XSS
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via "user-provided input."
CWE-79 Mar 19, 2010
CVE-2010-0465 EPSS 0.00
Sugarcrm - XSS
Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.
CWE-79 Mar 19, 2010
CVE-2010-1025 EPSS 0.00
TYPO3 tgm_newsletter 0.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1023 EPSS 0.00
TYPO3 taskcenter_recent <0.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the UserTask Center, Recent (taskcenter_recent) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1021 EPSS 0.00
Typo3 Quixplorer <1.7.1 - XSS
Cross-site scripting (XSS) vulnerability in the Typo3 Quixplorer (t3quixplorer) extension before 1.7.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1020 EPSS 0.00
TYPO3 sk_simplegallery <0.0.9 - XSS
Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1014 EPSS 0.00
TYPO3 reports_logview <1.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the Reports Logfile View (reports_logview) extension 1.2.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1011 EPSS 0.00
TYPO3 myDashboard <0.1.13 - XSS
Cross-site scripting (XSS) vulnerability in the myDashboard (mydashboard) extension 0.1.13 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1008 EPSS 0.00
TYPO3 chsellector <0.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Sellector.com Widget Integration (chsellector) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010
CVE-2010-1005 EPSS 0.00
TYPO3 YATSE <0.3.2 - XSS
Cross-site scripting (XSS) vulnerability in the Yet another TYPO3 search engine (YATSE) extension before 0.3.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 19, 2010