CVE & Exploit Intelligence Database

Updated 19m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
42,457 results Clear all
CVE-2008-4737 1 PoC Analysis EPSS 0.01
Noc2 Whodomlite - XSS
Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the dom parameter.
CWE-79 Oct 24, 2008
CVE-2008-4733 EPSS 0.00
Pressography WP Comment Remix Plugin < 1.4.3 - XSS
Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters.
CWE-79 Oct 24, 2008
CVE-2008-4730 EPSS 0.00
Phpmyid - XSS
Cross-site scripting (XSS) vulnerability in MyID.php in phpMyID 0.9 allows remote attackers to inject arbitrary web script or HTML via the openid_trust_root parameter and an inconsistent openid_return_to parameter, which is not properly handled in an error message.
CWE-79 Oct 24, 2008
CVE-2008-4727 1 PoC Analysis EPSS 0.06
Sungard Banner Student - XSS
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be sure.
CWE-79 Oct 24, 2008
CVE-2008-4725 1 PoC Analysis EPSS 0.14
Opera Browser - XSS
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.
CWE-79 Oct 23, 2008
CVE-2008-4724 EPSS 0.00
Google Chrome - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 23, 2008
CVE-2008-4723 EPSS 0.00
Mozilla Firefox - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 23, 2008
CVE-2008-4697 EPSS 0.01
Opera Browser < 9.60 - XSS
The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascript: URL in the context of the outermost page instead of the page that contains this URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
CWE-79 Oct 23, 2008
CVE-2008-4696 4 PoCs Analysis EPSS 0.62
Opera - XSS
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).
CWE-79 Oct 23, 2008
CVE-2008-4710 EPSS 0.00
Drupal Stock Module - XSS
Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 23, 2008
CVE-2008-4672 1 PoC Analysis EPSS 0.00
Goodlyrics Lyrics Script - XSS
Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 22, 2008
CVE-2008-4671 1 PoC Analysis EPSS 0.01
Wordpress MU - XSS
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.
CWE-79 Oct 22, 2008
CVE-2008-4670 1 PoC Analysis EPSS 0.00
ED Putal Clickbank Portal - XSS
Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 22, 2008
CVE-2008-4669 1 PoC Analysis EPSS 0.00
DAN Fletcher Recipe Script - XSS
Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 22, 2008
CVE-2008-4663 EPSS 0.00
Kumacchi KS Cgi Access Log - XSS
Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 22, 2008
CVE-2008-4661 EPSS 0.00
Typo3 Page Improvements < 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Page Improvements (sm_pageimprovements) 1.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 22, 2008
CVE-2008-4648 1 PoC Analysis EPSS 0.03
Elxis Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the error might be located in modules/mod_language.php, and index.php might be the interaction point.
CWE-79 Oct 22, 2008
CVE-2008-4637 EPSS 0.00
Cpcommerce < 1.2.3 - XSS
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is probably a variant of CVE-2008-4121.
CWE-79 Oct 21, 2008
CVE-2008-4121 EPSS 0.01
Cpcommerce < 1.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.
CWE-79 Oct 21, 2008
CVE-2007-4350 EPSS 0.01
HP SiteScope 9.0 - XSS
Cross-site scripting (XSS) vulnerability in the management interface in HP SiteScope 9.0 build 911 allows remote attackers to inject arbitrary web script or HTML via an SNMP trap message.
CWE-79 Oct 21, 2008