CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
42,457 results Clear all
CVE-2008-5566 1 PoC Analysis EPSS 0.06
Triangle Solutions PHP Multiple Newsletters 2.7 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Dec 15, 2008
CVE-2008-5556 EPSS 0.11
Microsoft Internet Explorer 8.0 Beta 2 - XSS
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design.
CWE-79 Dec 12, 2008
CVE-2008-5555 EPSS 0.15
Microsoft Internet Explorer 8.0 Beta 2 - XSS
Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
CWE-79 Dec 12, 2008
CVE-2008-5554 EPSS 0.14
Microsoft Internet Explorer 8.0 Beta 2 - XSS
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
CWE-79 Dec 12, 2008
CVE-2008-5553 EPSS 0.14
Microsoft Internet Explorer 8.0 Beta 2 - XSS
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
CWE-79 Dec 12, 2008
CVE-2008-5552 EPSS 0.08
Microsoft Internet Explorer 8.0 Beta 2 - XSS
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
CWE-79 Dec 12, 2008
CVE-2008-5551 1 PoC Analysis EPSS 0.32
Microsoft Internet Explorer 8.0 Beta 2 - XSS
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
CWE-79 Dec 12, 2008
CVE-2008-5487 1 PoC Analysis EPSS 0.03
TurnkeyForms Text Link Sales - XSS
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Dec 12, 2008
CVE-2008-5435 EPSS 0.00
PunBB <1.3.1 - XSS
Cross-site scripting (XSS) vulnerability in moderate.php in PunBB before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via a topic subject.
CWE-79 Dec 11, 2008
CVE-2008-5433 EPSS 0.00
PunBB <1.3.1 - XSS
Cross-site scripting (XSS) vulnerability in login.php in PunBB 1.3 and 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the password field.
CWE-79 Dec 11, 2008
CVE-2008-5432 EPSS 0.01
Moodle <1.6.8, <1.7.6, <1.8.7, <1.9.3 - XSS
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
CWE-79 Dec 11, 2008
CVE-2008-5399 EPSS 0.00
mvnForum <1.2.1 - XSS
Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CWE-79 Dec 10, 2008
CVE-2008-5304 1 PoC Analysis EPSS 0.06
TWiki <4.2.4 - XSS
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
CWE-79 Dec 10, 2008
CVE-2008-5338 1 PoC Analysis EPSS 0.03
Bandwebsite 1.5 - XSS
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
CWE-79 Dec 05, 2008
CVE-2008-5330 1 PoC Analysis EPSS 0.02
IBM Rational ClearCase <7.0.0.4-7.0.1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.
CWE-79 Dec 05, 2008
CVE-2008-5325 EPSS 0.00
IBM Rational ClearQuest <7.0.0.4, <7.0.1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2008
CVE-2008-5324 EPSS 0.00
IBM Rational ClearQuest <2007D, 2008 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 05, 2008
CVE-2008-2379 EPSS 0.01
Squirrelmail < 1.4.16 - XSS
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.
CWE-79 Dec 05, 2008
CVE-2008-5323 1 PoC Analysis EPSS 0.04
Wysi Wiki Wyg 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Dec 03, 2008
CVE-2008-5080 EPSS 0.00
Awstats < 6.8 - XSS
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
CWE-79 Dec 03, 2008