CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
42,457 results Clear all
CVE-2008-4893 1 PoC Analysis EPSS 0.00
Tribiq Cms - XSS
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 04, 2008
CVE-2008-4892 EPSS 0.00
Planetluc Mygallery - XSS
Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 04, 2008
CVE-2008-4891 EPSS 0.00
Planetluc Signme - XSS
Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 04, 2008
CVE-2008-4909 EPSS 0.00
Compact Cms < 1.1 - XSS
Cross-site request forgery (CSRF) vulnerability in CompactCMS 1.1 and earlier allows remote attackers to perform unauthorized actions as legitimate users via unspecified vectors.
CWE-79 Nov 04, 2008
CVE-2008-4888 1 PoC Analysis EPSS 0.06
Netrisk < 2.0 - XSS
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 04, 2008
CVE-2008-4876 1 PoC Analysis EPSS 0.06
Philips Electronics Voip841 Dect Phone - XSS
Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.
CWE-79 Nov 01, 2008
CVE-2008-4872 EPSS 0.00
Itechscripts Itechbids - XSS
Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 01, 2008
CVE-2008-4871 EPSS 0.00
MY Little Forum - XSS
Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbitrary web script or HTML via BBcode IMG tags.
CWE-79 Nov 01, 2008
CVE-2008-4805 EPSS 0.00
IBM Lotus Connections < 2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 31, 2008
CVE-2008-4803 1 PoC Analysis EPSS 0.00
Simple PHP Scripts Gallery - XSS
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 31, 2008
CVE-2008-4802 EPSS 0.00
Simple PHP Scripts Blog - XSS
Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 31, 2008
CVE-2008-4795 1 PoC Analysis EPSS 0.11
Opera < 9.61 - XSS
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.
CWE-79 Oct 30, 2008
CVE-2008-4775 1 PoC Analysis EPSS 0.08
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
CWE-79 Oct 28, 2008
CVE-2008-4774 1 PoC Analysis EPSS 0.03
Questwork Questcms - XSS
Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.
CWE-79 Oct 28, 2008
CVE-2008-4763 EPSS 0.00
Wikidsystems Wclient-php < 3.0-2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in sample.php in WiKID wClient-PHP 3.0-2 and earlier allow remote attackers to inject arbitrary web script or HTML via the PHP_SELF variable.
CWE-79 Oct 28, 2008
CVE-2008-4761 1 PoC Analysis EPSS 0.00
Kayako Esupport - XSS
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.
CWE-79 Oct 28, 2008
CVE-2008-4756 1 PoC Analysis EPSS 0.03
Php-daily - XSS
Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.
CWE-79 Oct 28, 2008
CVE-2008-4751 1 PoC Analysis EPSS 0.06
Epistream Ipei Guestbook - XSS
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.
CWE-79 Oct 27, 2008
CVE-2008-4745 EPSS 0.00
Uniwin Ecart Professional - XSS
Cross-site scripting (XSS) vulnerability in emailFriend.asp in Uniwin eCart Professional 2.0.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 27, 2008
CVE-2008-4742 1 PoC Analysis EPSS 0.00
Timetrex - XSS
Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters.
CWE-79 Oct 27, 2008