CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,495 CVEs tracked 53,311 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,933 Nuclei templates 48,945 vendors 42,609 researchers
42,486 results Clear all
CVE-2009-1729 2 PoCs Analysis EPSS 0.09
SUN Java System Communications Express - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.
CWE-79 May 21, 2009
CVE-2009-1593 1 PoC Analysis EPSS 0.00
Armorlogic Profense Web Application Firewall < 2.2.21 - XSS
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.
CWE-79 May 21, 2009
CVE-2009-1738 EPSS 0.00
Ivanjaros Feed Block - XSS
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."
CWE-79 May 20, 2009
CVE-2009-1735 1 PoC Analysis EPSS 0.05
Omnisoftsol Vidsharepro - XSS
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information.
CWE-79 May 20, 2009
CVE-2009-1732 EPSS 0.00
Richard Ellerbrock Ipplan - XSS
Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrary web script or HTML via the grp parameter.
CWE-79 May 20, 2009
CVE-2009-1418 EPSS 0.01
HP System Management Homepage < 3.0.0-68 - XSS
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 19, 2009
CVE-2009-1654 1 PoC Analysis EPSS 0.03
Easy-scripts Answer And Question Script - XSS
Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
CWE-79 May 16, 2009
CVE-2009-1581 EPSS 0.01
Squirrelmail - XSS
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.
CWE-79 May 14, 2009
CVE-2009-1578 EPSS 0.03
Squirrelmail - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).
CWE-79 May 14, 2009
CVE-2009-0162 1 PoC Analysis EPSS 0.02
Safari <3.2.3-4 Public Beta - XSS
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.
CWE-79 May 13, 2009
CVE-2009-0153 EPSS 0.12
ICU 4.0/3.x - XSS
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
CWE-79 May 13, 2009
CVE-2009-1623 1 PoC Analysis EPSS 0.00
Dew-code Dew-newphplinks - XSS
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.
CWE-79 May 12, 2009
CVE-2009-1620 1 PoC Analysis EPSS 0.00
Matachat - XSS
Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.
CWE-79 May 12, 2009
CVE-2009-1616 1 PoC Analysis EPSS 0.01
Coppermine Photo Gallery - XSS
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.
CWE-79 May 11, 2009
CVE-2009-1614 1 PoC Analysis EPSS 0.01
Gowondesigns Leap - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form). NOTE: some of these details are obtained from third party information.
CWE-79 May 11, 2009
CVE-2009-1607 1 PoC Analysis EPSS 0.02
Linkbase - XSS
Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator accesses the Users menu.
CWE-79 May 11, 2009
CVE-2009-1591 EPSS 0.00
CGI Rescue Cgi Web Mailer < 1.03 - XSS
CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.
CWE-79 May 08, 2009
CVE-2009-1588 EPSS 0.01
Cgi Rescue Minibbs - XSS
Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 08, 2009
CVE-2009-1583 1 PoC Analysis EPSS 0.08
R020 Tematres - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the (1) search form; (2) _expresion_de_busqueda, (3) letra, (4) estado_id, and (5) tema parameters to index.php; the (6) PATH_INFO to index.php; (7) unspecified parameters when editing a term as specified by the edit_id and tema parameters to index.php; and the (7) y, (8) ord, and (9) m parameters to sobre.php.
CWE-79 May 07, 2009
CVE-2009-1575 EPSS 0.01
Drupal - XSS
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
CWE-79 May 06, 2009