CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
42,457 results Clear all
CVE-2008-3581 1 PoC Analysis EPSS 0.03
Qsoft K-Links - XSS
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.
CWE-79 Aug 10, 2008
CVE-2008-3567 EPSS 0.01
Winamp <5.541 - XSS
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
CWE-79 Aug 10, 2008
CVE-2008-3565 6 PoCs Analysis EPSS 0.00
Meeting Room Booking System <1.2.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Aug 10, 2008
CVE-2008-3566 1 PoC Analysis EPSS 0.00
ZoneO-soft freeForum 1.7 - XSS
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Aug 10, 2008
CVE-2008-3574 1 PoC Analysis EPSS 0.02
Pluck 4.5.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) lang_install22, (4) titelkop, (5) lang_kop1, (6) lang_kop2, (7) lang_modules, (8) lang_kop4, (9) lang_kop15, (10) lang_kop5, and (11) titelkop parameters to (b) data/inc/header.php; the pluck_version and titelkop parameters to (c) data/inc/header2.php; and the (14) lang_theme6 parameter to (d) data/inc/themeinstall.php.
CWE-79 Aug 10, 2008
CVE-2008-3572 EPSS 0.00
Pligg 9.9.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5 allows remote attackers to inject arbitrary web script or HTML via the category parameter.
CWE-79 Aug 10, 2008
CVE-2008-3569 2 PoCs Analysis EPSS 0.01
XAMPP 1.6.7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.
CWE-79 Aug 10, 2008
CVE-2008-3559 2 PoCs Analysis EPSS 0.01
KAPhotoservice - XSS
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Aug 08, 2008
CVE-2008-3560 1 PoC Analysis EPSS 0.03
Kshop module 2.22 - XSS
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Aug 08, 2008
CVE-2008-3510 1 PoC Analysis EPSS 0.00
Crafty Syntax Live Help <2.14.6 - XSS
Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.
CWE-79 Aug 07, 2008
CVE-2008-3511 9 PoCs Analysis EPSS 0.00
Softbiz Image Gallery - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Aug 07, 2008
CVE-2008-3500 EPSS 0.00
Drupal 5.x - XSS
Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.
CWE-79 Aug 06, 2008
CVE-2008-3501 EPSS 0.01
Novell Groupwise 7.0.x - XSS
Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 06, 2008
CVE-2008-2939 EPSS 0.71
Apache HTTP Server < 2.0.63 - XSS
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
CWE-79 Aug 06, 2008
CVE-2008-3505 1 PoC Analysis EPSS 0.03
PolyPager <1.0 rc2 - XSS
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.
CWE-79 Aug 06, 2008
CVE-2008-3483 1 PoC Analysis EPSS 0.00
ScrewTurn Wiki <2.0.29-2.0.30 - XSS
Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.
CWE-79 Aug 05, 2008
CVE-2008-3482 EPSS 0.00
Panasonic Network Camera - XSS
Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Aug 05, 2008
CVE-2008-3457 EPSS 0.01
phpMyAdmin <2.11.8 - XSS
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.
CWE-79 Aug 04, 2008
CVE-2008-3448 1 PoC Analysis EPSS 0.04
csphonebook 1.02 - XSS
Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.
CWE-79 Aug 04, 2008
CVE-2008-1232 1 PoC Analysis EPSS 0.38
Apache Tomcat <6.0.17 - XSS
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
CWE-79 Aug 04, 2008