CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,495 CVEs tracked 53,311 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,933 Nuclei templates 48,945 vendors 42,609 researchers
42,486 results Clear all
CVE-2009-1220 1 PoC Analysis EPSS 0.20
Cisco Adaptive Security Appliance - XSS
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
CWE-79 Apr 01, 2009
CVE-2009-1218 1 PoC Analysis EPSS 0.02
SUN Java System Calendar Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.
CWE-79 Apr 01, 2009
CVE-2009-1204 3 PoCs Analysis EPSS 0.04
Tikiwiki Cms/groupware - XSS
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.
CWE-79 Apr 01, 2009
CVE-2008-6571 EPSS 0.00
Linpha < 1.3.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified vectors.
CWE-79 Mar 31, 2009
CVE-2008-6570 EPSS 0.01
Cybozu Garoon - XSS
Cross-site scripting (XSS) vulnerability in the RSS reader in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
CWE-79 Mar 31, 2009
CVE-2008-6567 EPSS 0.00
Gallarific - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comment, which is not properly handled during moderation, and (3) the tag parameter to gallery/tags.php.
CWE-79 Mar 31, 2009
CVE-2008-6565 1 PoC Analysis EPSS 0.00
Invision Power Services Invision Power Board < 2.3.1 - XSS
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.
CWE-79 Mar 31, 2009
CVE-2008-6562 2 PoCs Analysis EPSS 0.00
JAX Scripts Jax Linklists - XSS
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 31, 2009
CVE-2005-4879 1 PoC Analysis EPSS 0.00
Jax Guestbook <3.31 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.
CWE-79 Mar 31, 2009
CVE-2009-1175 EPSS 0.00
Banshee - XSS
Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.
CWE-79 Mar 31, 2009
CVE-2008-6550 1 PoC Analysis EPSS 0.01
Davidbourrier Glossaire - XSS
Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Mar 30, 2009
CVE-2008-6533 EPSS 0.00
Drupal - XSS
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CWE-79 Mar 26, 2009
CVE-2008-6529 1 PoC Analysis EPSS 0.02
Ezonescripts Living Local - XSS
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter.
CWE-79 Mar 26, 2009
CVE-2009-1150 EPSS 0.01
Phpmyadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.
CWE-79 Mar 26, 2009
CVE-2009-1070 1 PoC Analysis EPSS 0.02
Expressionengine - XSS
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
CWE-79 Mar 26, 2009
CVE-2009-1069 EPSS 0.00
Drupal Content Construction Kit - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
CWE-79 Mar 26, 2009
CVE-2009-1067 1 PoC Analysis EPSS 0.04
Getpixie Pixie Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.
CWE-79 Mar 26, 2009
CVE-2009-1091 EPSS 0.00
Rapidleech - XSS
Cross-site scripting (XSS) vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to inject arbitrary web script or HTML via the uploaded parameter.
CWE-79 Mar 25, 2009
CVE-2009-1081 EPSS 0.00
SUN Java System Identity Manager - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.
CWE-79 Mar 25, 2009
CVE-2009-1080 EPSS 0.00
SUN Java System Identity Manager - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.
CWE-79 Mar 25, 2009