CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
42,457 results Clear all
CVE-2008-2445 1 PoC Analysis EPSS 0.04
Wgcc Web Group Communication Center - XSS
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action.
CWE-79 May 27, 2008
CVE-2008-2450 EPSS 0.00
Inmedias Statistics - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 27, 2008
CVE-2008-2452 EPSS 0.00
Inmedias Questionaire < 1.2.0 - XSS
Cross-site scripting (XSS) vulnerability in the Questionaire (aka pbsurvey) extension 1.2.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 27, 2008
CVE-2008-2449 2 PoCs Analysis EPSS 0.00
Ikemcg Phpinstantgallery - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 May 27, 2008
CVE-2008-2458 1 PoC Analysis EPSS 0.00
4shared Starsgames Control Panel < 4.6.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.
CWE-79 May 27, 2008
CVE-2008-2333 1 PoC Analysis EPSS 0.01
Barracuda Networks Barracuda Spam Firewall < 3.5.11.020 - XSS
Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
CWE-79 May 23, 2008
CVE-2007-5496 EPSS 0.00
Selinux Setroubleshoot - XSS
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.
CWE-79 May 23, 2008
CVE-2007-5961 EPSS 0.00
Red Hat Ntwk <5.0.2 - XSS
Cross-site scripting (XSS) vulnerability in the Red Hat Network channel search feature, as used in RHN and Red Hat Network Satellite before 5.0.2, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 May 23, 2008
CVE-2008-2421 1 PoC Analysis EPSS 0.08
Sap Web Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.
CWE-79 May 23, 2008
CVE-2008-2302 EPSS 0.00
Django < 0.91.2 - XSS
Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.
CWE-79 May 23, 2008
CVE-2008-2410 EPSS 0.00
IBM Lotus Domino Web Server < 8.0 - XSS
Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 22, 2008
CVE-2008-2413 1 PoC Analysis EPSS 0.00
Acgv.free Acgv News - XSS
Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 May 22, 2008
CVE-2008-2414 1 PoC Analysis EPSS 0.00
Aguestbook AN Guestbook - XSS
Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.
CWE-79 May 22, 2008
CVE-2008-2397 EPSS 0.00
Dotcms - XSS
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 May 21, 2008
CVE-2008-2398 EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.00
Appserv < 2.5.10 - XSS
Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.
CWE-79 May 21, 2008
CVE-2008-2335 2 PoCs Analysis EPSS 0.11
Vastal Phpvid - XSS
Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.
CWE-79 May 19, 2008
CVE-2008-2344 EPSS 0.00
Typo3 Air Filemanager - XSS
Cross-site scripting (XSS) vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 19, 2008
CVE-2008-2295 1 PoC Analysis EPSS 0.03
Rgboard < 3.0.12 - XSS
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.
CWE-79 May 18, 2008
CVE-2008-2280 EPSS 0.00
Scriptphp Picengine - XSS
Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 May 16, 2008
CVE-2008-2272 EPSS 0.00
Aruba Networks Aruba Mobility Controller - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 16, 2008