CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,575 CVEs tracked 53,318 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,991 vendors 42,653 researchers
42,490 results Clear all
CVE-2009-4461 1 PoC Analysis EPSS 0.01
FlatPress 0.909 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.
CWE-79 Dec 30, 2009
CVE-2009-4460 EPSS 0.00
Auto-Surf Traffic Exchange Script 1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.
CWE-79 Dec 30, 2009
CVE-2009-4459 EPSS 0.00
Redmine <0.8.7 - XSS
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.
CWE-79 Dec 30, 2009
CVE-2009-4458 3 PoCs Analysis EPSS 0.02
FreePBX 2.5.2-2.6.0rc2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to admin/admin/config.php during a trunks display action, the (2) description parameter during an Add Zap Channel action, and (3) unspecified vectors during an Add Recordings action.
CWE-79 Dec 30, 2009
CVE-2009-4450 1 PoC Analysis EPSS 0.01
LiveZilla 3.1.8.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lat, (2) lng, and (3) zom parameters, which are not properly handled when processed with templates/map.tpl.
CWE-79 Dec 29, 2009
CVE-2009-4446 1 PoC Analysis EPSS 0.01
phpInstantGallery 1.1 - XSS
Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Dec 29, 2009
CVE-2009-1798 1 PoC Analysis EPSS 0.04
APC Network Management Card - XSS
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.
CWE-79 Dec 28, 2009
CVE-2009-4433 3 PoCs Analysis EPSS 0.03
IDevSpot iSupport <1.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.php and index.php; (c) the which parameter to function.php, or (d) the which parameter to index.php, related to knowledgebase_list.php. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 28, 2009
CVE-2009-4429 2 PoCs Analysis EPSS 0.01
Drupal <5.x-1.3, <6.x-1.3 - XSS
Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).
CWE-79 Dec 28, 2009
CVE-2009-4425 EPSS 0.00
iDevCart 1.09 - XSS
Cross-site scripting (XSS) vulnerability in index.php in iDevCart 1.09 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter in a browse action.
CWE-79 Dec 28, 2009
CVE-2009-4422 EPSS 0.00
Aditus Consulting JpGraph 3.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting JpGraph 3.0.6 allow remote attackers to inject arbitrary web script or HTML via a key to csim_in_html_ex1.php, and other unspecified vectors.
CWE-79 Dec 24, 2009
CVE-2009-4416 EPSS 0.01
phpGroupWare <0.9.16.014 - XSS
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.
CWE-79 Dec 24, 2009
CVE-2009-4408 EPSS 0.00
PyForum 1.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to inject arbitrary web script or HTML via crafted BBcode (1) img or (2) url tags, which are not properly handled when a post is viewed.
CWE-79 Dec 23, 2009
CVE-2009-4406 EPSS 0.00
APC Switched Rack PDU AP7932 B2 - XSS
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 or 3.7.0 on AOS 3.3.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the login_username parameter.
CWE-79 Dec 23, 2009
CVE-2009-4403 1 PoC Analysis EPSS 0.02
Rumba XML 1.8 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 23, 2009
CVE-2009-3581 EPSS 0.00
Sql-ledger - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Receivables menu item for Add Transaction, (2) the Description field in the Accounts Payable menu item for Add Transaction, or the name field in (3) the Customers menu item for Add Customer or (4) the Vendor menu item for Add Vendor.
CWE-79 Dec 23, 2009
CVE-2009-4400 EPSS 0.00
TYPO3 ste_parish_admin <0.1.3 - XSS
Cross-site scripting (XSS) vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009
CVE-2009-4398 EPSS 0.00
TYPO3 hs_religiousartgallery <0.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009
CVE-2009-4397 EPSS 0.00
TYPO3 pd_resources <0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009
CVE-2009-4395 EPSS 0.00
Random Prayer 2 <0.0.3 - XSS
Cross-site scripting (XSS) vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009