CVE & Exploit Intelligence Database

Updated 7m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
42,464 results Clear all
CVE-2008-5939 1 PoC Analysis EPSS 0.06
MODx CMS <0.9.6.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. NOTE: some sources list the id parameter as being affected, but this is probably incorrect based on the original disclosure.
CWE-79 Jan 22, 2009
CVE-2009-0245 EPSS 0.00
Usagi Project MyNETS <1.2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4629.
CWE-79 Jan 22, 2009
CVE-2009-0026 2 PoCs Analysis EPSS 0.40
Apache Jackrabbit <1.5.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
CWE-79 Jan 21, 2009
CVE-2008-5933 1 PoC Analysis EPSS 0.04
CMS ISWEB 3.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 21, 2009
CVE-2008-5918 1 PoC Analysis EPSS 0.09
WebSVN <2.0 - XSS
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Jan 21, 2009
CVE-2008-5917 EPSS 0.01
Horde Application Framework <3.3 - XSS
Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.
CWE-79 Jan 21, 2009
CVE-2008-3821 1 PoC Analysis EPSS 0.09
Cisco IOS <12.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
CWE-79 Jan 16, 2009
CVE-2008-5893 1 PoC Analysis EPSS 0.04
ClickAndEmail - XSS
Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.
CWE-79 Jan 12, 2009
CVE-2008-5891 1 PoC Analysis EPSS 0.00
Injader <2.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 12, 2009
CVE-2008-5889 1 PoC Analysis EPSS 0.01
Click&Rank - XSS
Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.
CWE-79 Jan 12, 2009
CVE-2009-0107 1 PoC Analysis EPSS 0.04
PHPAuctions - XSS
Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.
CWE-79 Jan 09, 2009
CVE-2009-0105 1 PoC Analysis EPSS 0.03
EZpack 4.2b2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.
CWE-79 Jan 09, 2009
CVE-2008-5879 1 PoC Analysis EPSS 0.04
Phpclanwebsite <1.23.3.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors.
CWE-79 Jan 08, 2009
CVE-2008-5869 1 PoC Analysis EPSS 0.03
Proxim Wireless Tsunami MP.11 2411 - XSS
Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated users to inject arbitrary web script or HTML via the system.sysName.0 SNMP OID.
CWE-79 Jan 08, 2009
CVE-2008-5858 EPSS 0.00
KnowledgeTree <3.5.4a - XSS
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
CWE-79 Jan 06, 2009
CVE-2008-5854 1 PoC Analysis EPSS 0.04
myPHPscripts Login Session 2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email parameters (aka the User form) in an ls_register action. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 06, 2009
CVE-2008-5845 EPSS 0.00
Six Apart Movable Type <4.23 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Six Apart Movable Type (MT) before 4.23 allow remote attackers to inject arbitrary web script or HTML via a (1) MTEntryAuthorUsername, (2) MTAuthorDisplayName, (3) MTEntryAuthorDisplayName, or (4) MTCommenterName field in a Profile View template; a (5) listing screen or (6) edit screen in the CMS app; (7) a TrackBack title, related to the HTML sanitization library; or (8) a user archive name (aka archive title) on a published Community Blog template.
CWE-79 Jan 05, 2009
CVE-2008-5842 EPSS 0.00
Fujitsu-Siemens WebTransactions - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via vectors associated with (1) a demo application shipped with WebTransactions and possibly (2) an unspecified "dynamic application."
CWE-79 Jan 05, 2009
CVE-2008-5814 EPSS 0.01
PHP <5.2.7 - XSS
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
CWE-79 Jan 02, 2009
CVE-2008-5808 EPSS 0.00
Six Apart MTE <1.56-4.23 - XSS
Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management."
CWE-79 Jan 02, 2009