CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,527 CVEs tracked 53,314 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,934 Nuclei templates 48,968 vendors 42,617 researchers
42,489 results Clear all
CVE-2009-2771 EPSS 0.00
Free Arcade Script 1.3 - XSS
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.
CWE-79 Aug 14, 2009
CVE-2008-6972 EPSS 0.00
Karen Stevenson Cck - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.
CWE-79 Aug 13, 2009
CVE-2008-6969 EPSS 0.00
Pentasoft Corp. Avactis Shopping Cart - XSS
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) CHECKOUT_CZ_BLOWFISH_KEY parameters.
CWE-79 Aug 13, 2009
CVE-2008-6946 1 PoC Analysis EPSS 0.04
Collabtive - XSS
Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via the project Name, which is not properly handled when the administrator performs an editform action, related to admin.php.
CWE-79 Aug 12, 2009
CVE-2008-6945 EPSS 0.01
Icdevgroup Interchange - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature.
CWE-79 Aug 12, 2009
CVE-2009-2739 EPSS 0.00
FreeNAS <0.69.2 - XSS
Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Aug 11, 2009
CVE-2009-2738 EPSS 0.00
FreeNAS <0.7RC1 - CSRF
Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
CWE-79 Aug 11, 2009
CVE-2008-6927 1 PoC Analysis EPSS 0.04
Cpanel - XSS
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action.
CWE-79 Aug 10, 2009
CVE-2008-6925 EPSS 0.00
Zenphoto - XSS
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Aug 10, 2009
CVE-2008-6924 1 PoC Analysis EPSS 0.02
Intelliants Esyndicat - XSS
Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters.
CWE-79 Aug 10, 2009
CVE-2008-6915 1 PoC Analysis EPSS 0.02
Zeeways Zeeproperty - XSS
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter.
CWE-79 Aug 07, 2009
CVE-2008-6906 1 PoC Analysis EPSS 0.01
Babbleboard - XSS
Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard 1.1.6 allows remote attackers to inject arbitrary web script or HTML via the username.
CWE-79 Aug 06, 2009
CVE-2008-6894 EPSS 0.00
3CX Phone System - XSS
Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition 6.1793 and 6.0.806.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fName and (2) fPassword parameters.
CWE-79 Aug 03, 2009
CVE-2008-6893 EPSS 0.00
Alt-n Worldclient - XSS
Cross-site scripting (XSS) vulnerability in Alt-N MDaemon WorldClient 10.0.2, when Internet Explorer 7 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted img tag.
CWE-79 Aug 03, 2009
CVE-2008-6891 3 PoCs Analysis EPSS 0.01
Codetoad Asp Forum Script - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.
CWE-79 Aug 03, 2009
CVE-2008-6888 1 PoC Analysis EPSS 0.02
Preprojects Pre Classified Listings - XSS
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.
CWE-79 Aug 03, 2009
CVE-2008-6885 EPSS 0.01
Xoops - XSS
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
CWE-79 Jul 31, 2009
CVE-2008-6879 EPSS 0.02
Apache Roller - XSS
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
CWE-79 Jul 30, 2009
CVE-2009-2636 EPSS 0.00
Kerio MailServer <6.7.0 - XSS
Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.
CWE-79 Jul 28, 2009
CVE-2009-2615 EPSS 0.00
DataCheck Solutions SitePal 1.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions SitePal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_admin_login.asp, (2) z_forgot.asp, and possibly unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jul 27, 2009