CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,552 CVEs tracked 53,317 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,973 vendors 42,623 researchers
42,489 results Clear all
CVE-2009-2733 2 PoCs Analysis EPSS 0.05
Achievo <1.4.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
CWE-79 Oct 16, 2009
CVE-2009-3030 EPSS 0.01
Symantec Securityexpressions Audit And Compliance Server < 4.1.1 - XSS
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
CWE-79 Oct 15, 2009
CVE-2009-3029 EPSS 0.01
Symantec Securityexpressions Audit And Compliance Server < 4.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages.
CWE-79 Oct 15, 2009
CVE-2009-2898 1 PoC Analysis EPSS 0.01
Springsource Application Management Suite - XSS
Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 13, 2009
CVE-2009-2897 EPSS 0.01
Springsource Application Management Suite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allow remote attackers to inject arbitrary web script or HTML via invalid values for numerical parameters, as demonstrated by an uncaught java.lang.NumberFormatException exception resulting from (1) the typeId parameter to mastheadAttach.do, (2) the eid parameter to Resource.do, and (3) the u parameter in a view action to admin/user/UserAdmin.do. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 13, 2009
CVE-2009-2684 2 PoCs Analysis EPSS 0.07
HP Printers - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
CWE-79 Oct 13, 2009
CVE-2009-3668 EPSS 0.00
Promosi-web Ardguest - XSS
Cross-site scripting (XSS) vulnerability in ardguest.php in Ardguest 1.8 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Oct 11, 2009
CVE-2009-3666 1 PoC Analysis EPSS 0.01
Nullam Blog - XSS
Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary web script or HTML via the e parameter in an error action.
CWE-79 Oct 11, 2009
CVE-2009-3653 EPSS 0.00
Darren OH Xml Sitemap - XSS
Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecified vectors, related to link path output.
CWE-79 Oct 09, 2009
CVE-2009-3652 EPSS 0.00
Moshe Weitzman Organic Groups - XSS
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a different issue than CVE-2008-3095.
CWE-79 Oct 09, 2009
CVE-2009-3651 EPSS 0.00
Mikeryan Browscap < 5.x-1.0 - XSS
Cross-site scripting (XSS) vulnerability in the "Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
CWE-79 Oct 09, 2009
CVE-2009-3650 EPSS 0.00
David Strauss Dex < 5.x-1.0 - XSS
Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 09, 2009
CVE-2009-3649 EPSS 0.00
Pbboard - XSS
Cross-site scripting (XSS) vulnerability in forums/index.php in Power Bulletin Board (PBBoard) 2.0.2 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a new_topic action.
CWE-79 Oct 09, 2009
CVE-2009-3648 EPSS 0.00
Apsivam Service Links - XSS
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.
CWE-79 Oct 09, 2009
CVE-2009-3647 1 PoC Analysis EPSS 0.00
Yabsoft Mega File Hosting Script - XSS
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 09, 2009
CVE-2009-3601 1 PoC Analysis EPSS 0.00
Scriptsez Ultimate Poll - XSS
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
CWE-79 Oct 08, 2009
CVE-2009-3599 1 PoC Analysis EPSS 0.01
Freewebscriptz Hubscript - XSS
Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitrary web script or HTML via the bid_id parameter.
CWE-79 Oct 08, 2009
CVE-2009-3598 1 PoC Analysis EPSS 0.01
Ecardmax.com Formxp - XSS
Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
CWE-79 Oct 08, 2009
CVE-2009-3594 EPSS 0.00
Blob Blog System - XSS
Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.
CWE-79 Oct 08, 2009
CVE-2009-3593 2 PoCs Analysis EPSS 0.01
Freewebscriptz Freelancers - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php.
CWE-79 Oct 08, 2009