CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
42,457 results Clear all
CVE-2008-4333 1 PoC Analysis EPSS 0.03
Cannot Php Infoboard - XSS
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.
CWE-79 Sep 30, 2008
CVE-2008-4326 EPSS 0.00
Phpmyadmin < 2.11.9.1 - XSS
The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.
CWE-79 Sep 30, 2008
CVE-2008-4320 3 PoCs Analysis EPSS 0.02
Opennms < 1.0.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp, and (3) the filter parameter to event/list.
CWE-79 Sep 29, 2008
CVE-2008-4120 1 PoC Analysis EPSS 0.06
Flatpress - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php.
CWE-79 Sep 29, 2008
CVE-2008-4196 EPSS 0.01
Opera Browser < 9.51 - XSS
Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 27, 2008
CVE-2008-4119 EPSS 0.01
Broadcom Service Desk - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk 11.2 and CMDB 11.0 through 11.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "multiple web forms."
CWE-79 Sep 27, 2008
CVE-2008-4066 EPSS 0.01
Mozilla Firefox - XSS
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."
CWE-79 Sep 24, 2008
CVE-2008-4065 EPSS 0.01
Mozilla Firefox < 2.0.0.17 - XSS
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
CWE-79 Sep 24, 2008
CVE-2008-3098 1 PoC Analysis EPSS 0.10
Fuzzylime CMS <3.03 - XSS
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.
CWE-79 Sep 24, 2008
CVE-2008-4152 EPSS 0.00
Drupal Talk < 5.x-1.2 - XSS
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title.
CWE-79 Sep 24, 2008
CVE-2008-4149 EPSS 0.00
Drupal Link TO US < 5.x-1.0 - XSS
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link page header" field.
CWE-79 Sep 24, 2008
CVE-2008-4147 EPSS 0.00
Drupal Mailsave < 5.x-3.2 - XSS
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.
CWE-79 Sep 24, 2008
CVE-2008-4140 1 PoC Analysis EPSS 0.00
Opensolution Quick.cart - XSS
Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.
CWE-79 Sep 24, 2008
CVE-2008-4139 1 PoC Analysis EPSS 0.00
Opensolution Quick.cms.lite - XSS
Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.
CWE-79 Sep 24, 2008
CVE-2008-4184 EPSS 0.00
Webcms Portal Edition - XSS
Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Sep 23, 2008
CVE-2008-4182 EPSS 0.00
Horde Turba Contact Manager H3 - XSS
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.
CWE-79 Sep 23, 2008
CVE-2008-4179 2 PoCs Analysis EPSS 0.02
Nooms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.
CWE-79 Sep 23, 2008
CVE-2008-4174 1 PoC Analysis EPSS 0.02
Benjamin KUZ Dynamic Mp3 Lister - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.
CWE-79 Sep 23, 2008
CVE-2008-4168 EPSS 0.00
Pro2col Stingray Fts - XSS
Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject arbitrary web script or HTML via the form_username parameter (aka user name field).
CWE-79 Sep 22, 2008
CVE-2008-4130 EPSS 0.01
Gallery < 2.2.5 - XSS
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
CWE-79 Sep 18, 2008