CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,575 CVEs tracked 53,318 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,991 vendors 42,653 researchers
42,490 results Clear all
CVE-2009-4391 EPSS 0.00
TYPO3 dr_blob 2.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the File list (dr_blob) extension 2.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009
CVE-2009-4388 EPSS 0.00
TYPO3 nl_listman 1.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the ListMan (nl_listman) extension 1.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 22, 2009
CVE-2009-4387 EPSS 0.01
ManageEngine PMP <6.1.6104 - XSS
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.
CWE-79 Dec 22, 2009
CVE-2009-4384 1 PoC Analysis EPSS 0.01
Scriptsez.net Ez Poll Hoster - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTML via the (1) pid parameter in a code action to index.php and the (2) uid parameter in a view action to profile.php.
CWE-79 Dec 22, 2009
CVE-2009-4382 1 PoC Analysis EPSS 0.02
PHPFABER CMS - XSS
Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web script or HTML via the mod parameter.
CWE-79 Dec 22, 2009
CVE-2009-4381 1 PoC Analysis EPSS 0.04
Million Pixel Script 3 - XSS
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 22, 2009
CVE-2009-4379 EPSS 0.00
Valarsoft Webmatic <3.0.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Valarsoft Webmatic before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-2924.
CWE-79 Dec 22, 2009
CVE-2009-4371 EPSS 0.00
Drupal Core <6.14-6.15 - XSS
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
CWE-79 Dec 21, 2009
CVE-2009-4370 EPSS 0.00
Drupal Core <6.15 - XSS
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
CWE-79 Dec 21, 2009
CVE-2009-4369 EPSS 0.00
Drupal Core <5.21, <6.15 - XSS
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
CWE-79 Dec 21, 2009
CVE-2009-4366 2 PoCs Analysis EPSS 0.01
ScriptsEz Ez Blog 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parameter in a bmonth action.
CWE-79 Dec 21, 2009
CVE-2009-4364 2 PoCs Analysis EPSS 0.00
ScriptsEz Ez Blog - XSS
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname parameter, related to the act and id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Dec 21, 2009
CVE-2009-4363 EPSS 0.00
Horde Application Framework < 3.3.5 - XSS
Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message. NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."
CWE-79 Dec 21, 2009
CVE-2009-4142 2 PoCs Analysis EPSS 0.17
PHP <5.2.12 - XSS
The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.
CWE-79 Dec 21, 2009
CVE-2009-3701 4 PoCs Analysis EPSS 0.02
Horde Application Framework < 3.3.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.
CWE-79 Dec 21, 2009
CVE-2009-4359 1 PoC Analysis EPSS 0.01
SmartMedia 0.85 Beta - XSS
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
CWE-79 Dec 20, 2009
CVE-2009-4352 EPSS 0.00
TransWARE Active! mail <2003.0139.0871 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters.
CWE-79 Dec 17, 2009
CVE-2009-4348 EPSS 0.00
NewsScript 1.3 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to inject arbitrary web script or HTML via the topic parameter in a topic action, a different vector than CVE-2006-2146.
CWE-79 Dec 17, 2009
CVE-2009-4347 EPSS 0.00
daloradius-users <0.9-8 - XSS
Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
CWE-79 Dec 17, 2009
CVE-2009-4346 EPSS 0.00
TYPO3 fe_rtenews <1.4.1 - XSS
Cross-site scripting (XSS) vulnerability in the Frontend news submitter with RTE (fe_rtenews) extension 1.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 17, 2009