CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
42,486 results Clear all
CVE-2009-0660 EPSS 0.00
Mahara <1.0.10, <1.1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.
CWE-79 Mar 11, 2009
CVE-2009-0862 EPSS 0.00
Tangocms < 2.2.3 - XSS
Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 10, 2009
CVE-2009-0861 EPSS 0.00
Denorastats Phpdenora < 1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information.
CWE-79 Mar 10, 2009
CVE-2009-0860 EPSS 0.00
Netcordia Netmri < 3.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.
CWE-79 Mar 10, 2009
CVE-2009-0857 EPSS 0.00
SUN Management Center - XSS
Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: this can be leveraged for access to the SunMC Web Console.
CWE-79 Mar 09, 2009
CVE-2009-0856 EPSS 0.00
IBM Websphere Application Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 09, 2009
CVE-2009-0855 1 PoC Analysis EPSS 0.25
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 09, 2009
CVE-2009-0781 EPSS 0.37
Apache Tomcat <6.0.18 - XSS
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
CWE-79 Mar 09, 2009
CVE-2009-0850 EPSS 0.00
Bitdefender Internet Security - XSS
Cross-site scripting (XSS) vulnerability in BitDefender Internet Security 2009 allows user-assisted remote attackers to inject arbitrary web script or HTML via the filename of a virus-infected file, as demonstrated by a filename inside a (1) rar or (2) zip archive file.
CWE-79 Mar 09, 2009
CVE-2008-6450 EPSS 0.00
Under Construction Baby Pc2m < 0.9.22.4 - XSS
Cross-site scripting (XSS) vulnerability in Under Construction, Baby (UCB) PC2M 0.9.22.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Mar 09, 2009
CVE-2008-6448 EPSS 0.00
Skyarc Mtcms Wysiwyg Editor - XSS
Cross-site scripting (XSS) vulnerability in install.cgi in SKYARC System MTCMS WYSIWYG Editor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 09, 2009
CVE-2008-6439 1 PoC Analysis EPSS 0.00
Abledating - XSS
Cross-site scripting (XSS) vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
CWE-79 Mar 06, 2009
CVE-2008-6437 2 PoCs Analysis EPSS 0.00
Lukas Waldauf Phpfreeforum < 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.
CWE-79 Mar 06, 2009
CVE-2008-6436 EPSS 0.01
Xerox Workcentre - XSS
Cross-site scripting (XSS) vulnerability in the Web Server in Xerox WorkCentre 7132, 7228, 7235, and 7245 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 06, 2009
CVE-2008-6435 2 PoCs Analysis EPSS 0.00
Phpsqlitecms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[home], (2) lang[admin_menu], and (3) lang[admin_menu_page_overview] parameters to cms/includes/header.inc.php; and the (4) lang[login_username] and (5) lang[login_password] parameters to cms/includes/login.inc.php.
CWE-79 Mar 06, 2009
CVE-2008-6433 EPSS 0.00
Blueriver Sava Cms < 5.0 - XSS
Cross-site scripting (XSS) vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.
CWE-79 Mar 06, 2009
CVE-2008-6431 3 PoCs Analysis EPSS 0.00
Bmforum - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to newtem/header/bsd01header.php.
CWE-79 Mar 06, 2009
CVE-2008-6428 EPSS 0.00
Kaya - XSS
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
CWE-79 Mar 06, 2009
CVE-2008-6416 EPSS 0.00
Greensql-console < 0.3.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL-Console before 0.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "internal pages."
CWE-79 Mar 06, 2009
CVE-2008-6413 EPSS 0.00
Ticklespace Answers Module - XSS
Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.
CWE-79 Mar 06, 2009