CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
42,457 results Clear all
CVE-2008-3917 1 PoC Analysis EPSS 0.03
Ovidentia 6.6.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.
CWE-79 Sep 04, 2008
CVE-2008-3101 1 PoC Analysis EPSS 0.07
vtiger CRM 5.0.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.
CWE-79 Sep 03, 2008
CVE-2008-3881 EPSS 0.00
ZoneMinder <1.23.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files.
CWE-79 Sep 02, 2008
CVE-2008-3886 EPSS 0.00
dotProject 2.1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.
CWE-79 Sep 02, 2008
CVE-2008-3884 EPSS 0.00
Blogn BURO GUN <1.9.7 - XSS
Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-6176.
CWE-79 Sep 02, 2008
CVE-2008-2929 EPSS 0.01
Fedora Directory Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.
CWE-79 Aug 29, 2008
CVE-2008-3874 EPSS 0.00
Lussumo Vanilla <1.1.5-rc1 - XSS
Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details are obtained from third party information.
CWE-79 Aug 29, 2008
CVE-2008-3860 EPSS 0.00
IBM Lotus Quickr 8.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.
CWE-79 Aug 29, 2008
CVE-2008-3849 EPSS 0.00
Civic Website Manager <1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in the calendar controller in Civic Website Manager before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving (1) month, (2) day, and (3) year fields.
CWE-79 Aug 27, 2008
CVE-2008-3847 EPSS 0.00
AN Guestbook <0.7.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 27, 2008
CVE-2008-3850 1 PoC Analysis EPSS 0.00
Accellion File Transfer FTA_7_0_135 - XSS
Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html.
CWE-79 Aug 27, 2008
CVE-2008-3846 EPSS 0.00
mysql-lists <1.2 - XSS
Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 27, 2008
CVE-2008-3739 EPSS 0.01
La!Cooda WIZ <1.4.0 & LacoodaST <2.1.3 - XSS
Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.
CWE-79 Aug 27, 2008
CVE-2008-3842 EPSS 0.11
Microsoft .NET Framework - XSS
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.
CWE-79 Aug 27, 2008
CVE-2008-3843 EPSS 0.12
Microsoft .NET Framework - XSS
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
CWE-79 Aug 27, 2008
CVE-2008-3841 EPSS 0.00
Freeway eCommerce <1.4.1.171 - XSS
Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway eCommerce 1.4.1.171 allows remote attackers to inject arbitrary web script or HTML via the search_link parameter.
CWE-79 Aug 27, 2008
CVE-2008-3740 EPSS 0.00
Drupal <5.10,6.4 - XSS
Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 27, 2008
CVE-2008-3741 EPSS 0.00
Drupal <5.10, <6.4 - XSS
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.
CWE-79 Aug 27, 2008
CVE-2008-3782 EPSS 0.00
ACG-PTP 1.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ Entry.
CWE-79 Aug 26, 2008
CVE-2008-3779 1 PoC Analysis EPSS 0.04
Five Star Review Script - XSS
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.
CWE-79 Aug 26, 2008