CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
42,457 results Clear all
CVE-2008-3422 EPSS 0.01
Mono 2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
CWE-79 Jul 31, 2008
CVE-2008-3404 1 PoC Analysis EPSS 0.05
MJGuest 6.8 GT - XSS
Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.
CWE-79 Jul 31, 2008
CVE-2008-3391 2 PoCs Analysis EPSS 0.01
Web Wiz Forum 9.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.
CWE-79 Jul 31, 2008
CVE-2008-3397 6.1 MEDIUM EPSS 0.00
Runesoft Cerberus CMS <3.1.4.0.9 - XSS
Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS before 3_1.4_0.9 allows remote attackers to inject arbitrary web script or HTML via a cerberus_user cookie.
CWE-79 Jul 31, 2008
CVE-2008-3398 1 PoC Analysis EPSS 0.06
XRMS CRM 1.99.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.
CWE-79 Jul 31, 2008
CVE-2008-3394 EPSS 0.00
BookMine - XSS
Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.
CWE-79 Jul 31, 2008
CVE-2008-3381 EPSS 0.00
moin/MoinMoin 1.6.3-1.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 30, 2008
CVE-2008-3380 1 PoC Analysis EPSS 0.05
MyioSoft EasyBookMarker 4.0(tr) - XSS
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.
CWE-79 Jul 30, 2008
CVE-2008-3367 EPSS 0.00
Web Wiz Rich Text Editor <4.03 - XSS
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
CWE-79 Jul 30, 2008
CVE-2008-3379 EPSS 0.00
Snark VisualPic 0.3.1 - XSS
Cross-site scripting (XSS) vulnerability in Snark VisualPic 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the pic parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jul 30, 2008
CVE-2008-3100 1 PoC Analysis EPSS 0.09
Owl Intranet Knowledgebase <0.95 - XSS
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.
CWE-79 Jul 29, 2008
CVE-2008-3353 EPSS 0.00
Pure Software Lore <1.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.
CWE-79 Jul 28, 2008
CVE-2008-3342 EPSS 0.00
MyioSoft EasyPublish 3.0tr - XSS
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.
CWE-79 Jul 28, 2008
CVE-2008-3344 EPSS 0.00
MyioSoft EasyE-Cards 3.5(tr), 3.10a - XSS
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a allow remote attackers to inject arbitrary web script or HTML via the (1) ResultHtml, (2) dir, (3) SenderName, (4) RecipientName, (5) SenderMail, and (6) RecipientMail parameters.
CWE-79 Jul 28, 2008
CVE-2008-3340 EPSS 0.00
Jobbex JobSite - XSS
Cross-site scripting (XSS) vulnerability in search_result.cfm in Jobbex JobSite allows remote attackers to inject arbitrary web script or HTML via the searchFor variable (possibly the opt parameter.)
CWE-79 Jul 28, 2008
CVE-2008-3348 EPSS 0.00
MyioSoft EasyDynamicPages <3.0 - XSS
Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter.
CWE-79 Jul 28, 2008
CVE-2008-3331 1 PoC Analysis EPSS 0.01
Mantis <1.1.2 - XSS
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
CWE-79 Jul 27, 2008
CVE-2008-3336 EPSS 0.00
PunBB <1.2.19 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PunBB before 1.2.19 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) include/parser.php and (2) moderate.php.
CWE-79 Jul 27, 2008
CVE-2008-3334 EPSS 0.00
MyBB <1.2.14 - XSS
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.
CWE-79 Jul 27, 2008
CVE-2008-3328 EPSS 0.01
Trac <0.10.5 - XSS
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Jul 27, 2008