CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,552 CVEs tracked 53,317 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,973 vendors 42,623 researchers
42,489 results Clear all
CVE-2009-4032 2 PoCs Analysis EPSS 0.07
Cacti 0.8.7e - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.
CWE-79 Nov 29, 2009
CVE-2009-4078 EPSS 0.01
Redmine <0.8.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2009
CVE-2009-4069 EPSS 0.00
GForge <4.7.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 24, 2009
CVE-2009-3303 EPSS 0.00
Gforge - XSS
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
CWE-79 Nov 24, 2009
CVE-2009-4065 EPSS 0.00
Drupal Strongarm <6.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.
CWE-79 Nov 24, 2009
CVE-2009-4064 EPSS 0.00
Drupal Gallery Assist <6.x-1.7 - XSS
Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.
CWE-79 Nov 24, 2009
CVE-2009-4063 EPSS 0.00
Drupal OG <5.x-4.0, <5.x-3.4 - XSS
Cross-site scripting (XSS) vulnerability in the Subgroups for Organic Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified node titles.
CWE-79 Nov 24, 2009
CVE-2009-4062 EPSS 0.00
Drupal Printfriendly <6.x-1.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 24, 2009
CVE-2009-4061 EPSS 0.00
Drupal 6.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Agreement module 6.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 24, 2009
CVE-2009-4052 EPSS 0.00
IBM Rational App Dev <7.0.0.10 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.
CWE-79 Nov 23, 2009
CVE-2009-4047 6 PoCs Analysis EPSS 0.01
PHD Help Desk 1.43 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the PATH_INFO to area_list.php; (8) the q_registros parameter to area_list.php; (9) the PATH_INFO to atributo.php; the (10) pagina, (11) q_registros, and (12) orden parameters to atributo_list.php; (13) an arbitrary parameter name beginning with "sentido" to atributo_list.php; and (14) the PATH_INFO to caso_insert.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 23, 2009
CVE-2009-4043 EPSS 0.00
Drupal <6.x-2.4, <5.x-2.4 - XSS
Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.
CWE-79 Nov 20, 2009
CVE-2009-4042 EPSS 0.00
RootCandy theme <6.x-1.5 - XSS
Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.
CWE-79 Nov 20, 2009
CVE-2009-4040 EPSS 0.00
phpMyFAQ <2.0.17 & <2.5.2 - XSS
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.
CWE-79 Nov 20, 2009
CVE-2009-4039 1 PoC Analysis EPSS 0.02
Piwigo <2.0.6 - XSS
Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 20, 2009
CVE-2009-4038 EPSS 0.00
NCH Software Axon Virtual PBX <2.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or (2) oncancel parameter to the logon program. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 20, 2009
CVE-2009-3892 EPSS 0.00
Best Practical Solutions RT <3.6.9, <3.8.5 & 3.4.6-3.8.4 - XSS
Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through 3.8.4 versions allows remote attackers to inject arbitrary web script or HTML via certain Custom Fields.
CWE-79 Nov 17, 2009
CVE-2009-3891 EPSS 0.01
WordPress <2.8.6 - XSS
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
CWE-79 Nov 17, 2009
CVE-2009-3950 EPSS 0.00
Bractus SunTrack - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to newprofile.html; the (2) firstname, (3) lastname, and (4) company parameters to signup/signup.html; and the (5) firstname, (6) lastname, and (7) address[0].street1 parameters to contact.html.
CWE-79 Nov 16, 2009
CVE-2009-3566 1 PoC Analysis EPSS 0.05
Mcafee Intrushield Network Security Manager < 5.1.7.74 - XSS
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
CWE-79 Nov 13, 2009