CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
42,464 results Clear all
CVE-2008-6061 1 PoC Analysis EPSS 0.01
Techsmith Camtasia Studio <5 - XSS
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader parameter.
CWE-79 Feb 05, 2009
CVE-2008-6060 1 PoC Analysis EPSS 0.03
Shockwave Flash - XSS
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter.
CWE-79 Feb 05, 2009
CVE-2009-0430 1 PoC Analysis EPSS 0.01
Active Bids - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.
CWE-79 Feb 05, 2009
CVE-2009-0424 EPSS 0.00
ANG Guestbook <0.7.7 - XSS
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.
CWE-79 Feb 05, 2009
CVE-2009-0354 EPSS 0.01
Mozilla Firefox <3.0.6 - XSS
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
CWE-79 Feb 04, 2009
CVE-2008-6056 EPSS 0.00
World Recipe 2.11 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to recipedetail.aspx, and the (3) catid parameter to validatefieldlength.aspx.
CWE-79 Feb 04, 2009
CVE-2008-6047 EPSS 0.00
ADbNewsSender <1.5.2 - XSS
Cross-site scripting (XSS) vulnerability in ADbNewsSender before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) subscribing and (2) unsubscribing.
CWE-79 Feb 04, 2009
CVE-2009-0413 EPSS 0.00
RoundCube Webmail <0.2 - XSS
Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.
CWE-79 Feb 03, 2009
CVE-2009-0404 EPSS 0.01
Bioinformatics htmLawed <1.1.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7.
CWE-79 Feb 03, 2009
CVE-2008-6044 1 PoC Analysis EPSS 0.00
xt:Commerce <3.0.4 - XSS
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
CWE-79 Feb 03, 2009
CVE-2008-6041 EPSS 0.00
Dataspade 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Index.asp in Dataspade 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ViewName, (2) TableName, (3) OrderBy, and (4) FilterField parameters.
CWE-79 Feb 03, 2009
CVE-2008-6035 EPSS 0.00
Achievo 1.3.2-STABLE - XSS
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2-STABLE allows remote attackers to inject arbitrary web script or HTML via the atknodetype parameter.
CWE-79 Feb 03, 2009
CVE-2008-6034 1 PoC Analysis EPSS 0.00
Achievo 1.3.2 - XSS
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkaction parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 03, 2009
CVE-2008-6027 EPSS 0.00
BLUEPAGE CMS <2.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters.
CWE-79 Feb 03, 2009
CVE-2009-0393 1 PoC Analysis EPSS 0.00
Motorola Wimax modem CPEi300 - XSS
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.
CWE-79 Feb 03, 2009
CVE-2009-0273 EPSS 0.01
Novell GroupWise WebAccess <8.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.
CWE-79 Feb 02, 2009
CVE-2009-0378 1 PoC Analysis EPSS 0.00
Joomla! com_beamospetition 1.0.12 - XSS
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.
CWE-79 Feb 02, 2009
CVE-2009-0204 EPSS 0.01
HP Select Access 6.1-6.2 - XSS
Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 30, 2009
CVE-2009-0338 1 PoC Analysis EPSS 0.02
DMXReady Blog Manager - XSS
Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.
CWE-79 Jan 29, 2009
CVE-2009-0335 1 PoC Analysis EPSS 0.03
Katy Whitton BlogIt! - XSS
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.
CWE-79 Jan 29, 2009