CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,575 CVEs tracked 53,318 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,991 vendors 42,653 researchers
42,490 results Clear all
CVE-2010-0357 EPSS 0.01
IBM Lotus Web Content Management - XSS
Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Jan 20, 2010
CVE-2009-4616 1 PoC Analysis EPSS 0.00
MYRE Holiday Rental Manager - XSS
Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.
CWE-79 Jan 18, 2010
CVE-2010-0349 EPSS 0.00
C-3.co.jp Webcalenderc3 < 0.32 - XSS
Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.
CWE-79 Jan 15, 2010
CVE-2010-0347 EPSS 0.00
Typo3 VD Gemomap < 0.3.1 - XSS
Cross-site scripting (XSS) vulnerability in the VD / Geomap (vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0346 EPSS 0.00
Typo3 Mimi Tipfriends < 0.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0345 EPSS 0.00
Typo3 Majordomo < 1.1.3 - XSS
Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0335 EPSS 0.00
Francisco Cifuentes Vote For TT News < 1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0331 EPSS 0.00
Stefan Tannhaeuser Tv21 Talkshow < 1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0328 EPSS 0.00
Rastislav Birka Cs2 Unitconv - XSS
Cross-site scripting (XSS) vulnerability in the Unit Converter (cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0327 EPSS 0.00
Julian Kleinhans KJ Imagelightbox2 < 2.0.0 - XSS
Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490.
CWE-79 Jan 15, 2010
CVE-2010-0326 EPSS 0.00
Francois Suter Devlog < 2.9.1 - XSS
Cross-site scripting (XSS) vulnerability in the Developer log (devlog) extension 2.9.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 15, 2010
CVE-2010-0321 1 PoC Analysis EPSS 0.02
Jamit Job Board - XSS
Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.
CWE-79 Jan 15, 2010
CVE-2010-0320 EPSS 0.00
X10media Glitter Central Script - XSS
Cross-site scripting (XSS) vulnerability in submitlink.php in Glitter Central Script allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
CWE-79 Jan 15, 2010
CVE-2010-0319 1 PoC Analysis EPSS 0.02
Docmint - XSS
Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 15, 2010
CVE-2009-4612 1 PoC Analysis EPSS 0.00
Mort Bay Jetty 6.1.x-6.1.21 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
CWE-79 Jan 13, 2010
CVE-2009-4610 1 PoC Analysis EPSS 0.00
Mort Bay Jetty 6.x-7.0.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.
CWE-79 Jan 13, 2010
CVE-2009-4608 EPSS 0.01
Canon IT Solutions Inc. ACCESSGUARDIAN <3.5.6 - XSS
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc. ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to authentication.
CWE-79 Jan 13, 2010
CVE-2009-4602 EPSS 0.00
Drupal Randomizer <6.x-1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 12, 2010
CVE-2009-4601 1 PoC Analysis EPSS 0.01
Zeeways ZeeJobsite 3x - XSS
Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter.
CWE-79 Jan 12, 2010
CVE-2009-4596 1 PoC Analysis EPSS 0.01
PHP Inventory <1.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action.
CWE-79 Jan 12, 2010