CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
42,457 results Clear all
CVE-2008-5290 1 PoC Analysis EPSS 0.04
Clean CMS 1.5 - XSS
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Dec 01, 2008
CVE-2008-5278 EPSS 0.03
WordPress <2.6.5 - XSS
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
CWE-79 Nov 28, 2008
CVE-2008-5271 1 PoC Analysis EPSS 0.04
SyndeoCMS 2.6.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
CWE-79 Nov 28, 2008
CVE-2008-5266 1 PoC Analysis EPSS 0.01
GlassFish 2 UR2 b04 - XSS
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.
CWE-79 Nov 28, 2008
CVE-2008-5264 1 PoC Analysis EPSS 0.04
Tornado Knowledge Retrieval System <4.2 - XSS
Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action.
CWE-79 Nov 28, 2008
CVE-2008-5228 EPSS 0.00
IBM WCM <6.1 - XSS
Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded."
CWE-79 Nov 25, 2008
CVE-2008-5225 3 PoCs Analysis EPSS 0.04
Xerox DocuShare 6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.
CWE-79 Nov 25, 2008
CVE-2008-5224 EPSS 0.00
Kent Web Mart <1.61 - XSS
Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2008
CVE-2008-5214 1 PoC Analysis EPSS 0.03
ClanLite 2.2006.05.20 - XSS
Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.
CWE-79 Nov 24, 2008
CVE-2008-5211 1 PoC Analysis EPSS 0.05
Sphider 1.3.4 - XSS
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.
CWE-79 Nov 24, 2008
CVE-2008-5205 EPSS 0.00
wellyblog - XSS
Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.
CWE-79 Nov 21, 2008
CVE-2008-5203 1 PoC Analysis EPSS 0.02
PowerAward 1.1.0 RC1 - XSS
Cross-site scripting (XSS) vulnerability in external_vote.php in PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the l_vote_done parameter.
CWE-79 Nov 21, 2008
CVE-2008-5202 1 PoC Analysis EPSS 0.03
OTManager CMS 24a - XSS
Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS 24a allows remote attackers to inject arbitrary web script or HTML via the conteudo parameter.
CWE-79 Nov 21, 2008
CVE-2008-5193 1 PoC Analysis EPSS 0.04
Philboard 1.14,1.2 - XSS
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.
CWE-79 Nov 21, 2008
CVE-2008-5172 EPSS 0.00
Yazd Forum Software 3.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 19, 2008
CVE-2008-5164 2 PoCs Analysis EPSS 0.01
The Rat CMS Pre-Alpha 2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) viewarticle.php and (b) viewarticle2.php and the (2) PATH_INFO to viewarticle.php.
CWE-79 Nov 19, 2008
CVE-2008-5126 1 PoC Analysis EPSS 0.02
Boutikone Cms - XSS
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
CWE-79 Nov 18, 2008
CVE-2008-5119 EPSS 0.00
Scripts4profit Dxshopcart - XSS
Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
CWE-79 Nov 18, 2008
CVE-2008-5114 EPSS 0.00
SUN Java System Identity Manager - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 18, 2008
CVE-2008-5098 EPSS 0.00
SUN Java System Messaging Server - XSS
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904.
CWE-79 Nov 17, 2008