CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
42,457 results Clear all
CVE-2008-4481 EPSS 0.00
Redmine < 0.7.2 - XSS
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 08, 2008
CVE-2008-4393 1 PoC Analysis EPSS 0.01
Verisign Kontiki Delivery Management System < 5.0 - XSS
Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.
CWE-79 Oct 07, 2008
CVE-2008-4456 1 PoC Analysis EPSS 0.06
Mysql - XSS
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
CWE-79 Oct 06, 2008
CVE-2008-4450 EPSS 0.00
Apache Friends Xampp - XSS
Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for Windows 1.6.8 allows remote attackers to inject arbitrary web script or HTML via the (1) dbserver, (2) host, (3) user, (4) password, (5) database, and (6) table parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 06, 2008
CVE-2008-4447 1 PoC Analysis EPSS 0.02
Positive Software H-sphere - XSS
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.
CWE-79 Oct 06, 2008
CVE-2008-4446 EPSS 0.01
Nucleus < 3.31 - XSS
Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 06, 2008
CVE-2008-4438 1 PoC Analysis EPSS 0.00
Datafeed Studio - XSS
Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 03, 2008
CVE-2008-4435 2 PoCs Analysis EPSS 0.00
Rmsoft Downloads Plus Module - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
CWE-79 Oct 03, 2008
CVE-2008-4432 1 PoC Analysis EPSS 0.02
Rmsoft Minishop Module - XSS
Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.
CWE-79 Oct 03, 2008
CVE-2008-4426 3 PoCs Analysis EPSS 0.01
Phlatline Personal Information Manager - XSS
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action.
CWE-79 Oct 03, 2008
CVE-2008-4424 1 PoC Analysis EPSS 0.00
Domain Group Network Goocms - XSS
Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inject arbitrary web script or HTML via the s parameter in a comments action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 03, 2008
CVE-2008-4408 EPSS 0.01
Mediawiki - XSS
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via the useskin parameter to an unspecified component.
CWE-79 Oct 03, 2008
CVE-2008-2236 EPSS 0.00
Blosxom < 2.1.1 - XSS
Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the flav parameter (flavour variable). NOTE: some of these details are obtained from third party information.
CWE-79 Oct 03, 2008
CVE-2008-2831 EPSS 0.00
Mailmarshal E10000 Appliance - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the delegated spam management feature in the Spam Quarantine Management (SQM) component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow user-assisted remote authenticated users to inject arbitrary web script or HTML via (1) the list of blocked senders or (2) the list of safe senders.
CWE-79 Oct 02, 2008
CVE-2008-4372 1 PoC Analysis EPSS 0.03
Availscript Article Script - XSS
Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.
CWE-79 Oct 01, 2008
CVE-2008-4370 1 PoC Analysis EPSS 0.03
Availscript Photo Album - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php.
CWE-79 Oct 01, 2008
CVE-2008-4365 EPSS 0.00
Siteman < 1.1.11 - XSS
Cross-site scripting (XSS) vulnerability in search.php in Siteman 1.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Sep 30, 2008
CVE-2008-4349 1 PoC Analysis EPSS 0.02
S0nic Paranews - XSS
Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) page parameter in a details action.
CWE-79 Sep 30, 2008
CVE-2008-4337 EPSS 0.00
Bitweaver - XSS
Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to (1) edit.php and (2) list.php in articles/; (3) list_blogs.php and (4) rankings.php in blogs/; (5) calendar/index.php; (6) calendar.php, (7) index.php, and (8) list_events.php in events/; (9) index.php and (10) list_galleries.php in fisheye/; (11) liberty/list_content.php; (12) newsletters/edition.php; (13) pigeonholes/list.php; (14) recommends/index.php; (15) rss/index.php; (16) stars/index.php; (17) users/remind_password.php; (18) wiki/orphan_pages.php; and (19) stats/index.php, different vectors than CVE-2007-0526 and CVE-2005-4379. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Sep 30, 2008
CVE-2008-4336 1 PoC Analysis EPSS 0.03
Constantin Charissis Atomic Photo Album - XSS
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.
CWE-79 Sep 30, 2008