CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
42,457 results Clear all
CVE-2008-2571 EPSS 0.00
Limesurvey < 1.70 - XSS
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
CWE-79 Jun 06, 2008
CVE-2008-2563 EPSS 0.00
Samtodo - XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML via the (a) tid parameter in a main.taskeditor edit action, and the (b) completed parameter in a main.default action, to index.php.
CWE-79 Jun 06, 2008
CVE-2008-2557 EPSS 0.00
Cre Loaded < 6.2.13.1 - XSS
Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Links and (2) Links Submit pages.
CWE-79 Jun 05, 2008
CVE-2008-2553 EPSS 0.01
Slash < r_2_5_0_94 - XSS
Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.
CWE-79 Jun 05, 2008
CVE-2008-1947 EPSS 0.59
Apache Tomcat <6.0.17 - XSS
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
CWE-79 Jun 04, 2008
CVE-2008-2533 1 PoC Analysis EPSS 0.03
Fkrauthan Phoenix View Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget parameter to (a) admin/admin_frame.php and the (2) conf parameter to (b) gbuch.admin.php, (c) links.admin.php, (d) menue.admin.php, (e) news.admin.php, and (f) todo.admin.php in admin/module/.
CWE-79 Jun 03, 2008
CVE-2008-2525 EPSS 0.00
Typo3 Rlmp Eventdb < 1.1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Event Database (aka rlmp_eventdb) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 03, 2008
CVE-2008-2526 EPSS 0.00
Typo3 WT Gallery < 2.62 - XSS
Cross-site scripting (XSS) vulnerability in the WT Gallery (aka wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 03, 2008
CVE-2008-2527 EPSS 0.00
Actualscripts Actualanalyzer Gold < 2.78 - XSS
Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to inject arbitrary web script or HTML via the language parameter.
CWE-79 Jun 03, 2008
CVE-2008-2518 EPSS 0.01
SUN Java System Web Server - XSS
Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the next parameter.
CWE-79 Jun 03, 2008
CVE-2008-1036 EPSS 0.03
Apple Mac OS X - XSS
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
CWE-79 Jun 02, 2008
CVE-2008-2505 1 PoC Analysis EPSS 0.03
Simpel Side Weblosninger - XSS
Cross-site scripting (XSS) vulnerability in result.php in Simpel Side Weblosning 1 through 4 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 May 29, 2008
CVE-2008-2507 1 PoC Analysis EPSS 0.00
Brown Bear Software Calcium - XSS
Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action.
CWE-79 May 29, 2008
CVE-2008-2508 1 PoC Analysis EPSS 0.00
TR Script News - XSS
Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.
CWE-79 May 29, 2008
CVE-2008-2500 EPSS 0.00
Mambo Mostlyce < 2 - XSS
Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 29, 2008
CVE-2008-2496 1 PoC Analysis EPSS 0.04
Quate Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in admin/, and (4) upgrade/index.php.
CWE-79 May 28, 2008
CVE-2008-2490 EPSS 0.00
Typo3 KJ Imagelightbox2 < 1.4.2 - XSS
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input."
CWE-79 May 28, 2008
CVE-2008-2494 EPSS 0.00
Pancake Zina - XSS
Cross-site scripting (XSS) vulnerability in index.php in Zina 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via the l parameter.
CWE-79 May 28, 2008
CVE-2008-2485 EPSS 0.00
Pcpin Chat < 6.11 - XSS
Cross-site scripting (XSS) vulnerability in the URL redirection script (inc/url_redirection.inc.php) in PCPIN Chat before 6.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 May 28, 2008
CVE-2008-2493 1 PoC Analysis EPSS 0.01
Badongo Campus Bulletin Board - XSS
Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML via the review parameter.
CWE-79 May 28, 2008