CVE & Exploit Intelligence Database

Updated 11m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,640 CVEs tracked 53,321 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,006 vendors 42,664 researchers
42,493 results Clear all
CVE-2010-0716 EPSS 0.05
Microsoft SharePoint <2010 - XSS
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
CWE-79 Feb 26, 2010
CVE-2010-0714 1 PoC Analysis EPSS 0.02
IBM WebSphere Portal <6.1.5 - XSS
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.
CWE-79 Feb 26, 2010
CVE-2010-0706 1 PoC Analysis EPSS 0.01
Subex Nikira - XSS
Cross-site scripting (XSS) vulnerability in the login/prompt component in Subex Nikira Fraud Management System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Feb 25, 2010
CVE-2010-0704 EPSS 0.00
IBM WebSphere Portal 6.0.1.5 wp6015_008_01 - XSS
Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.
CWE-79 Feb 25, 2010
CVE-2010-0640 EPSS 0.00
CA Ehealth Performance Manager - XSS
Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.
CWE-79 Feb 24, 2010
CVE-2010-0703 1 PoC Analysis EPSS 0.06
PortWise SSL VPN 4.6 - XSS
Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter.
CWE-79 Feb 23, 2010
CVE-2010-0700 1 PoC Analysis EPSS 0.06
WampServer 2.0i - XSS
Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CWE-79 Feb 23, 2010
CVE-2010-0699 EPSS 0.00
VideoSearchScript Pro 3.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CWE-79 Feb 23, 2010
CVE-2010-0697 EPSS 0.00
Drupal iTweak Upload module <6.x-1.2/<6.x-2.3 - XSS
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
CWE-79 Feb 23, 2010
CVE-2009-3036 1 PoC Analysis EPSS 0.01
Symantec IM Manager - XSS
Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 23, 2010
CVE-2010-0695 1 PoC Analysis EPSS 0.00
BASIC-CMS - XSS
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.
CWE-79 Feb 23, 2010
CVE-2009-4651 1 PoC Analysis EPSS 0.00
Webee Comments 1.1.1-2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.
CWE-79 Feb 22, 2010
CVE-2010-0675 1 PoC Analysis EPSS 0.03
Bgsvetionik Bgs Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 22, 2010
CVE-2009-4649 EPSS 0.00
geccBBlite 0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.
CWE-79 Feb 22, 2010
CVE-2010-0162 EPSS 0.01
Mozilla Firefox - XSS
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
CWE-79 Feb 22, 2010
CVE-2009-4647 EPSS 0.00
Accellion Secure File Transfer Appliance <7.0.296 - XSS
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
CWE-79 Feb 19, 2010
CVE-2010-0641 1 PoC Analysis EPSS 0.02
Cisco Collaboration Server - XSS
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.
CWE-79 Feb 17, 2010
CVE-2010-0636 EPSS 0.00
K5N Webcalendar - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 12, 2010
CVE-2010-0617 EPSS 0.00
Myshell Evalsmsi - XSS
Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 11, 2010
CVE-2010-0615 EPSS 0.01
Myshell Evalsmsi - XSS
Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 11, 2010