CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
42,464 results Clear all
CVE-2008-3358 EPSS 0.01
SAP NetWeaver - Web Dynpro WD - XSS
Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document.
CWE-79 Jan 28, 2009
CVE-2008-6004 1 PoC Analysis EPSS 0.00
AJ Auction Pro Platinum 2 - XSS
Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter.
CWE-79 Jan 28, 2009
CVE-2008-5999 EPSS 0.00
Ajax Checklist module <5.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the ajax_checklist filter.
CWE-79 Jan 28, 2009
CVE-2008-5996 EPSS 0.00
Simplenews <6.x-1.0-beta4 - XSS
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.
CWE-79 Jan 28, 2009
CVE-2008-5995 EPSS 0.00
TYPO3 sr_freecap <1.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 28, 2009
CVE-2008-5994 EPSS 0.00
Check Point Connectra NGX R62 HFA_01 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 28, 2009
CVE-2009-0312 EPSS 0.01
MoinMoin <1.8.1 - XSS
Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.
CWE-79 Jan 28, 2009
CVE-2009-0303 EPSS 0.00
Web Help Desk <9.1.18 - XSS
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
CWE-79 Jan 27, 2009
CVE-2009-0285 1 PoC Analysis EPSS 0.02
BBSXP <5.13 - XSS
Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Jan 27, 2009
CVE-2009-0283 1 PoC Analysis EPSS 0.02
Oblog - XSS
Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Jan 27, 2009
CVE-2008-5979 1 PoC Analysis EPSS 0.04
Ocean12 Mailing List Manager Gold - XSS
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.
CWE-79 Jan 27, 2009
CVE-2008-5976 1 PoC Analysis EPSS 0.02
PHP JOBWEBSITE PRO - XSS
Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.
CWE-79 Jan 27, 2009
CVE-2008-5971 1 PoC Analysis EPSS 0.01
i-Net Solution Orkut Clone - XSS
Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
CWE-79 Jan 27, 2009
CVE-2009-0260 1 PoC Analysis EPSS 0.03
MoinMoin <1.8.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).
CWE-79 Jan 23, 2009
CVE-2008-5961 EPSS 0.00
Tribiq CMS Community <5.0.11E - XSS
Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID parameter in a document action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 23, 2009
CVE-2009-0257 EPSS 0.01
TYPO3 4.0.0-4.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.
CWE-79 Jan 22, 2009
CVE-2009-0248 1 PoC Analysis EPSS 0.03
Katy Whitton RankEm - XSS
Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.
CWE-79 Jan 22, 2009
CVE-2009-0247 EPSS 0.00
53KF Web IM - XSS
The server for 53KF Web IM 2009 Home, Professional, and Enterprise editions relies on client-side protection mechanisms against cross-site scripting (XSS), which allows remote attackers to conduct XSS attacks by using a modified client to send a crafted IM message, related to the msg variable.
CWE-79 Jan 22, 2009
CVE-2008-5944 1 PoC Analysis EPSS 0.02
NavBoard 16 (2.6.0) - XSS
Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter.
CWE-79 Jan 22, 2009
CVE-2008-5942 EPSS 0.00
MODx <0.9.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2) "username input." NOTE: vector 2 may be related to CVE-2008-5939.
CWE-79 Jan 22, 2009