CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,527 CVEs tracked 53,314 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,934 Nuclei templates 48,968 vendors 42,617 researchers
42,489 results Clear all
CVE-2009-2343 EPSS 0.00
Zoph <0.7.0.6 - XSS
Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Jul 07, 2009
CVE-2009-2342 EPSS 0.00
CMME <1.22 - XSS
Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field.
CWE-79 Jul 07, 2009
CVE-2008-6850 EPSS 0.00
Php-fusion - XSS
Cross-site scripting (XSS) vulnerability in messages.php in PHP-Fusion 6.01.17 and 7.00.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 07, 2009
CVE-2008-6848 2 PoCs Analysis EPSS 0.08
W2B Phpgreetcards - XSS
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML via the category parameter in a select action.
CWE-79 Jul 07, 2009
CVE-2009-2330 1 PoC Analysis EPSS 0.00
CMS Chainuk <1.2 - XSS
Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.
CWE-79 Jul 05, 2009
CVE-2009-2327 1 PoC Analysis EPSS 0.00
KerviNet Forum <1.1 - XSS
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.
CWE-79 Jul 05, 2009
CVE-2009-2324 EPSS 0.00
FCKeditor <2.6.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.
CWE-79 Jul 05, 2009
CVE-2009-2322 EPSS 0.00
Axesstel MV 410R - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 05, 2009
CVE-2009-2316 EPSS 0.01
IBM Tivoli Identity Manager <5.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.
CWE-79 Jul 05, 2009
CVE-2007-6728 EPSS 0.00
XMB 1.5 - XSS
Cross-site scripting (XSS) vulnerability in XMB 1.5 allows remote attackers to inject arbitrary web script or HTML via the MSN field during user registration.
CWE-79 Jul 05, 2009
CVE-2009-2302 1 PoC Analysis EPSS 0.02
Aardvark Topsites PHP <5.2.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
CWE-79 Jul 02, 2009
CVE-2008-6847 1 PoC Analysis EPSS 0.02
Preproject Pre Asp Job Board - XSS
Cross-site scripting (XSS) vulnerability in Employee/emp_login.asp in Pre ASP Job Board allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CWE-79 Jul 02, 2009
CVE-2009-2292 EPSS 0.01
Appleple a-News 2.32 - XSS
Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 01, 2009
CVE-2009-2289 1 PoC Analysis EPSS 0.00
Arcade Trade Script 1.0 beta - XSS
Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action.
CWE-79 Jul 01, 2009
CVE-2009-2284 EPSS 0.01
phpMyAdmin <3.2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
CWE-79 Jul 01, 2009
CVE-2009-2283 EPSS 0.00
Sun Java Web Console <3.0.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 01, 2009
CVE-2009-2268 EPSS 0.00
Sun Java System Access Manager - XSS
Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 01, 2009
CVE-2009-2241 1 PoC Analysis EPSS 0.02
ASP Inline Corporate Calendar - XSS
Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
CWE-79 Jun 27, 2009
CVE-2009-2240 EPSS 0.00
AD2000 free-sw leger <1.6.4 - XSS
Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 27, 2009
CVE-2008-6839 2 PoCs Analysis EPSS 0.00
Tgs-cms Tgs Content Management - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id parameters to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jun 27, 2009