CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
42,457 results Clear all
CVE-2008-2994 2 PoCs Analysis EPSS 0.01
Phpeasydata - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.
CWE-79 Jul 03, 2008
CVE-2008-2997 1 PoC Analysis EPSS 0.03
Gravityboardx Gravity Board X - XSS
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.
CWE-79 Jul 03, 2008
CVE-2008-2998 EPSS 0.00
Drupal Aggregation Module - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 03, 2008
CVE-2008-2984 1 PoC Analysis EPSS 0.03
Cmreams Cms - XSS
Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.
CWE-79 Jul 02, 2008
CVE-2008-2962 1 PoC Analysis EPSS 0.03
Myblog - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.
CWE-79 Jul 02, 2008
CVE-2008-2987 3 PoCs Analysis EPSS 0.01
Benjacms Benja Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php, and (3) admin_edit_topmenu.php in admin/.
CWE-79 Jul 02, 2008
CVE-2008-2980 1 PoC Analysis EPSS 0.01
Homeph Design - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
CWE-79 Jul 02, 2008
CVE-2008-2967 1 PoC Analysis EPSS 0.06
Yektaweb Academic Web Tools < 1.4.2.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to login.php and the (2) glb_sid parameter to hta/htmlarea.js.php, and allow remote authenticated users to inject arbitrary web script or HTML via an unspecified field in room.php.
CWE-79 Jul 02, 2008
CVE-2008-2960 EPSS 0.01
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
CWE-79 Jul 02, 2008
CVE-2008-2979 1 PoC Analysis EPSS 0.03
Ourvideo Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web script or HTML via the (1) top_page and (2) end_page parameters.
CWE-79 Jul 02, 2008
CVE-2008-2975 1 PoC Analysis EPSS 0.03
Tinx Cms - XSS
Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
CWE-79 Jul 02, 2008
CVE-2008-2973 1 PoC Analysis EPSS 0.03
MM Chat - XSS
Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters.
CWE-79 Jul 02, 2008
CVE-2008-2965 1 PoC Analysis EPSS 0.03
Jaxbot Jaxultrabb < 2.0 - XSS
Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter.
CWE-79 Jul 02, 2008
CVE-2008-2462 EPSS 0.03
Caucho Resin < 3.0.25 - XSS
Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
CWE-79 Jun 30, 2008
CVE-2008-2924 EPSS 0.00
Valarsoft Webmatic < 2.7.1 - XSS
Cross-site scripting (XSS) vulnerability in Webmatic before 2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 30, 2008
CVE-2008-2923 EPSS 0.00
Lyris List Manager - XSS
Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the words parameter.
CWE-79 Jun 30, 2008
CVE-2008-2911 1 PoC Analysis EPSS 0.04
Contenido Contendio - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.
CWE-79 Jun 30, 2008
CVE-2008-2871 1 PoC Analysis EPSS 0.00
Pegames - XSS
Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jun 26, 2008
CVE-2008-2855 1 PoC Analysis EPSS 0.03
Ownrs - XSS
Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Jun 25, 2008
CVE-2008-2849 EPSS 0.00
Drupal Trailscout Module - XSS
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 25, 2008