CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,552 CVEs tracked 53,317 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,973 vendors 42,623 researchers
42,489 results Clear all
CVE-2009-3565 2 PoCs Analysis EPSS 0.06
Mcafee Intrushield Network Security Manager < 5.1.7.74 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.
CWE-79 Nov 13, 2009
CVE-2009-2823 EPSS 0.00
Apple Mac OS X < 10.6.1 - XSS
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
CWE-79 Nov 10, 2009
CVE-2009-2820 1 PoC Analysis EPSS 0.02
Apple Mac OS X < 10.6.1 - XSS
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.
CWE-79 Nov 10, 2009
CVE-2009-3618 EPSS 0.01
Viewvc - XSS
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the view parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 10, 2009
CVE-2009-3919 EPSS 0.00
Drupal crmngp <6.x-1.12 - XSS
Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."
CWE-79 Nov 09, 2009
CVE-2009-3918 EPSS 0.00
Zoomify <6.x-1.4 - XSS
Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the node title.
CWE-79 Nov 09, 2009
CVE-2009-3917 EPSS 0.00
Drupal S5 Presentation Player <6.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field that is copied to the HTML HEAD element.
CWE-79 Nov 09, 2009
CVE-2009-3916 EPSS 0.00
Node Hierarchy <6.x-1.3 - XSS
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a child node title.
CWE-79 Nov 09, 2009
CVE-2009-3915 EPSS 0.00
Drupal Link module <6.x-2.7 - XSS
Cross-site scripting (XSS) vulnerability in the "Separate title and URL" formatter in the Link module 5.x before 5.x-2.6 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the link title field.
CWE-79 Nov 09, 2009
CVE-2009-3914 EPSS 0.00
Drupal 5.x - XSS
Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation.
CWE-79 Nov 09, 2009
CVE-2009-3911 1 PoC Analysis EPSS 0.01
TFTgallery 0.13 - XSS
Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter.
CWE-79 Nov 09, 2009
CVE-2009-3905 EPSS 0.00
e-Courier CMS - XSS
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 06, 2009
CVE-2009-3903 EPSS 0.00
ManageEngine Netflow Analyzer 7.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5 build 7500 allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) section parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 06, 2009
CVE-2009-3901 1 PoC Analysis EPSS 0.01
e-Courier CMS - XSS
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors.
CWE-79 Nov 06, 2009
CVE-2009-3300 EPSS 0.00
Internet2 Identity Provider - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.
CWE-79 Nov 06, 2009
CVE-2009-3858 1 PoC Analysis EPSS 0.02
GejoSoft - XSS
Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI in photos/tags.
CWE-79 Nov 04, 2009
CVE-2009-3856 1 PoC Analysis EPSS 0.01
Twilight CMS <4.1 - XSS
Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 04, 2009
CVE-2009-3299 EPSS 0.01
Mahara < 1.0.12 - XSS
Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 03, 2009
CVE-2009-3833 1 PoC Analysis EPSS 0.00
Tftgallery - XSS
Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
CWE-79 Nov 02, 2009
CVE-2009-3636 EPSS 0.00
Typo3 < 4.0.12 - XSS
Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Nov 02, 2009