CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
42,464 results Clear all
CVE-2009-0455 1 PoC Analysis EPSS 0.01
glFusion <1.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.
CWE-79 Feb 11, 2009
CVE-2008-6108 1 PoC Analysis EPSS 0.00
Galatolo WebManager 1.0 - XSS
Cross-site scripting (XSS) vulnerability in result.php in Galatolo WebManager (GWM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the key parameter.
CWE-79 Feb 10, 2009
CVE-2008-6105 EPSS 0.00
IBM Workplace - XSS
Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 10, 2009
CVE-2009-0467 1 PoC Analysis EPSS 0.03
Profense Web App Firewall <2.6.3 - XSS
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage action.
CWE-79 Feb 10, 2009
CVE-2009-0466 EPSS 0.00
Vivvo CMS <4.1.1 - XSS
Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.
CWE-79 Feb 10, 2009
CVE-2009-0417 EPSS 0.00
Agavi <0.11.6-1.0.0 beta 8 - XSS
Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.
CWE-79 Feb 10, 2009
CVE-2009-0502 EPSS 0.00
Snoopy 1.2.3 - XSS
Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.
CWE-79 Feb 10, 2009
CVE-2009-0500 EPSS 0.00
Moodle <1.6.9-1.9.4 - XSS
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.
CWE-79 Feb 10, 2009
CVE-2009-0496 3 PoCs Analysis EPSS 0.14
Ignite Realtime Openfire 3.6.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.
CWE-79 Feb 10, 2009
CVE-2009-0488 EPSS 0.00
Phorum <5.2.10 - XSS
Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 09, 2009
CVE-2009-0487 EPSS 0.00
Mahara <1.0.9 - XSS
Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.
CWE-79 Feb 09, 2009
CVE-2009-0481 EPSS 0.00
Bugzilla <3.22.7-3.3.2 - XSS
Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.
CWE-79 Feb 09, 2009
CVE-2008-6097 1 PoC Analysis EPSS 0.00
WikyBlog <1.7.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to index.php/Edit/Main/Home, (3) to parameter to index.php/Special/Main/WhatLinksHere, (4) user parameter to index.php/Special/Main/UserEdits, and (5) the PATH_INFO to index.php.
CWE-79 Feb 09, 2009
CVE-2008-6096 EPSS 0.00
Juniper NetScreen ScreenOS <5.4r10-6.1r2 - XSS
Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page.
CWE-79 Feb 09, 2009
CVE-2008-6095 EPSS 0.00
OpenNMS 1.5.94 - XSS
Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter.
CWE-79 Feb 09, 2009
CVE-2008-6094 1 PoC Analysis EPSS 0.00
Celoxis Technologies Celoxis - XSS
Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter.
CWE-79 Feb 09, 2009
CVE-2009-0472 EPSS 0.00
Rockwell Automation ControlLogix 1756-ENBT/A - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 06, 2009
CVE-2009-0470 1 PoC Analysis EPSS 0.05
Cisco IOS 12.4(23) - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
CWE-79 Feb 06, 2009
CVE-2008-6087 1 PoC Analysis EPSS 0.04
Camera Life 2.6.2b4 - XSS
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
CWE-79 Feb 06, 2009
CVE-2008-6062 EPSS 0.08
Adobe Dreamweaver - XSS
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.
CWE-79 Feb 05, 2009