CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,640 CVEs tracked 53,321 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,006 vendors 42,664 researchers
42,493 results Clear all
CVE-2009-4729 1 PoC Analysis EPSS 0.02
x10 Adult Media Script 1.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php.
CWE-79 Mar 18, 2010
CVE-2010-0979 EPSS 0.00
Obsession-Design Image-Gallery (ODIG) 1.1 - XSS
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
CWE-79 Mar 16, 2010
CVE-2010-0971 1 PoC Analysis EPSS 0.01
ATutor 1.6.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 16, 2010
CVE-2010-0963 EPSS 0.00
dl Download Ticket Service <0.7 - XSS
Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 16, 2010
CVE-2009-4717 6 PoCs Analysis EPSS 0.00
Gonafish WebStatCaffe - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML via the (1) host parameter to stat/host.php, nodayshow parameter to (2) mostvisitpage.php and (3) visitorduration.php in stat/, (4) nopagesmost parameter to stat/mostvisitpagechart.php, and date parameter to (5) pageviewers.php, (6) pageviewerschart.php, and (7) referer.php in stat/.
CWE-79 Mar 15, 2010
CVE-2009-4716 EPSS 0.00
EDGEPHP EZWebSearch - XSS
Cross-site scripting (XSS) vulnerability in results.php in EDGEPHP EZWebSearch allows remote attackers to inject arbitrary web script or HTML via the language parameter.
CWE-79 Mar 15, 2010
CVE-2009-4715 EPSS 0.00
Real Time Currency Exchange - XSS
Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter.
CWE-79 Mar 15, 2010
CVE-2009-4714 1 PoC Analysis EPSS 0.01
XOOPS Celepar - XSS
Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.
CWE-79 Mar 15, 2010
CVE-2009-4713 2 PoCs Analysis EPSS 0.02
Qas module for XOOPS Celepar - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the cod_categoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO to (3) categoria.php and (4) index.php.
CWE-79 Mar 15, 2010
CVE-2009-4707 EPSS 0.00
TYPO3 Gobernalia <0.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 15, 2010
CVE-2009-4706 EPSS 0.00
TYPO3 mailform <0.9.24 - XSS
Cross-site scripting (XSS) vulnerability in the Mailform (mailform) extension before 0.9.24 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 15, 2010
CVE-2009-4705 EPSS 0.00
Twitter Search <0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 15, 2010
CVE-2009-4699 1 PoC Analysis EPSS 0.03
SkaDate Dating - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/auth.php and (2) file_uploader.php.
CWE-79 Mar 15, 2010
CVE-2010-0959 EPSS 0.00
IBM ENOVIA SmarTeam 5 - XSS
Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.
CWE-79 Mar 10, 2010
CVE-2009-4697 1 PoC Analysis EPSS 0.01
RadNICS Gold 5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter in a ulist action and the (2) fid parameter in a view_forum action.
CWE-79 Mar 10, 2010
CVE-2009-4694 1 PoC Analysis EPSS 0.01
RadScripts RadLance Gold 7.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the fid parameter in a view_forum action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 10, 2010
CVE-2009-4692 1 PoC Analysis EPSS 0.01
RadScripts RadLance Gold 7.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the pr parameter in a ulist action.
CWE-79 Mar 10, 2010
CVE-2009-4690 2 PoCs Analysis EPSS 0.04
YourFreeWorld Programs Rating Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rate.php and (2) postcomments.php.
CWE-79 Mar 10, 2010
CVE-2009-4688 1 PoC Analysis EPSS 0.01
PHP Shopping Cart Selling Website Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.
CWE-79 Mar 10, 2010
CVE-2009-4686 1 PoC Analysis EPSS 0.03
phplemon AdQuick 2.2.1 - XSS
Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the red_url parameter.
CWE-79 Mar 10, 2010