CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
42,457 results Clear all
CVE-2008-5095 EPSS 0.00
Novell Identity Manager Roles Based Provisioning Module - XSS
Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Nov 14, 2008
CVE-2008-5093 EPSS 0.01
Novell Edirectory < 8.8 - XSS
Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Nov 14, 2008
CVE-2008-5068 1 PoC Analysis EPSS 0.00
Kkeim Kmita Gallery - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter to index.php and the (2) searchtext parameter to search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 13, 2008
CVE-2008-5067 1 PoC Analysis EPSS 0.00
Kkeim Kmita Catalogue - XSS
Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 13, 2008
CVE-2008-5061 1 PoC Analysis EPSS 0.06
Smolinari Mini Web Calendar - XSS
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.
CWE-79 Nov 13, 2008
CVE-2008-5059 1 PoC Analysis EPSS 0.04
Modernbill < 4.4 - XSS
Cross-site scripting (XSS) vulnerability in index.php in ModernBill 4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript event in the new_language parameter in a login action.
CWE-79 Nov 13, 2008
CVE-2008-5056 EPSS 0.00
Activecampaign Triolive < 1.58.6 - XSS
Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.
CWE-79 Nov 13, 2008
CVE-2008-5019 EPSS 0.13
Mozilla Firefox < 2.0.0.18 - XSS
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
CWE-79 Nov 13, 2008
CVE-2008-5043 EPSS 0.00
IBM Metrica Service Assurance Framework - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.
CWE-79 Nov 12, 2008
CVE-2008-5039 1 PoC Analysis EPSS 0.02
Php-nuke League Module - XSS
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.
CWE-79 Nov 12, 2008
CVE-2008-5026 EPSS 0.15
Microsoft Sharepoint Server - XSS
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
CWE-79 Nov 10, 2008
CVE-2008-5011 EPSS 0.00
IBM Lotus < quickr - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.
CWE-79 Nov 10, 2008
CVE-2008-4823 EPSS 0.18
Adobe Flash Player < 9.0.124.0 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.
CWE-79 Nov 10, 2008
CVE-2008-4818 EPSS 0.18
Adobe Flash Player < 9.0.124.0 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.
CWE-79 Nov 10, 2008
CVE-2008-4931 1 PoC Analysis EPSS 0.02
Firmchannel Digital Signage - XSS
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
CWE-79 Nov 05, 2008
CVE-2008-4928 EPSS 0.01
Mybb - XSS
Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the ajax option to request a JavaScript redirect. NOTE: this can be leveraged to execute PHP code and bypass cross-site request forgery (CSRF) protection.
CWE-79 Nov 04, 2008
CVE-2008-4918 1 PoC Analysis EPSS 0.26
Sonicwall Sonicos Enhanced < 4.0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
CWE-79 Nov 04, 2008
CVE-2008-4903 EPSS 0.00
Typo < 5.1.3 - XSS
Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.
CWE-79 Nov 04, 2008
CVE-2008-4898 EPSS 0.00
Planetluc Rateme - XSS
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.
CWE-79 Nov 04, 2008
CVE-2008-4896 1 PoC Analysis EPSS 0.00
Logz - XSS
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the art parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 04, 2008