CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
42,457 results Clear all
CVE-2008-1978 EPSS 0.00
Ubercart 5.x <5.x-1.0 rc3 - XSS
Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node titles related to unspecified product features, a different vector than CVE-2008-1428.
CWE-79 Apr 27, 2008
CVE-2008-1974 1 PoC Analysis EPSS 0.02
Horde Kronolith <2.1.7, Horde Groupware <1.0.6 - XSS
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Apr 27, 2008
CVE-2008-1969 3 PoCs Analysis EPSS 0.01
Cezanne 6.5.1-7 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7) CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d) PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters to (e) PeopleWeb/Cards/PayrollCard.asp, and the (10) FolderTemplateId and (11) FolderTemplateName parameters to (f) PeopleWeb/CznDocFolder/CznDFStartProcess.asp.
CWE-79 Apr 27, 2008
CVE-2008-1972 EPSS 0.00
Exponent CMS <0.96.6-GA20071003 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the user account creation feature in Exponent CMS 0.96.6-GA20071003 and earlier, when the Allow Registration? configuration option is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) firstname, (3) lastname, and (4) e-mail address fields. NOTE: some of these details are obtained from third party information.
CWE-79 Apr 27, 2008
CVE-2008-1967 1 PoC Analysis EPSS 0.01
Cezanne 6.5.1-7 - XSS
Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.
CWE-79 Apr 27, 2008
CVE-2008-1956 1 PoC Analysis EPSS 0.00
Wikepage Opus 13 2007.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.
CWE-79 Apr 25, 2008
CVE-2008-1960 EPSS 0.00
ContRay 3.x - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/contray/search.cgi in ContRay 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 25, 2008
CVE-2008-1955 1 PoC Analysis EPSS 0.00
MyBoard 1.0.12 - XSS
Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. information.
CWE-79 Apr 25, 2008
CVE-2008-1953 EPSS 0.00
Magnolia Enterprise Edition <1.1.5 - XSS
Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 25, 2008
CVE-2008-1941 EPSS 0.00
Akiva WebBoard 8.0 - XSS
Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the form field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 25, 2008
CVE-2008-1385 1 PoC Analysis EPSS 0.07
Serendipity <1.3.1 - XSS
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
CWE-79 Apr 23, 2008
CVE-2008-1916 EPSS 0.00
Ubercart 5.x <5.x-1.0-rc1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text fields intended for the (1) address and (2) order information, which are later displayed on the order view page and unspecified other administrative pages, a different vulnerability than CVE-2008-1428.
CWE-79 Apr 23, 2008
CVE-2008-1386 EPSS 0.01
Serendipity (S9Y) 1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for exploitation of this issue might be limited.
CWE-79 Apr 23, 2008
CVE-2008-1917 3 PoCs Analysis EPSS 0.00
AMFPHP 1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 23, 2008
CVE-2008-1906 1 PoC Analysis EPSS 0.06
cpCommerce 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.
CWE-79 Apr 22, 2008
CVE-2008-1894 EPSS 0.01
BusinessObjects InfoView XI <FixPack 3.5 - XSS
Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote attackers to inject arbitrary web script or HTML via the cms parameter.
CWE-79 Apr 18, 2008
CVE-2008-1896 1 PoC Analysis EPSS 0.07
Carbon Communities <2.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.
CWE-79 Apr 18, 2008
CVE-2008-1892 EPSS 0.00
Blogator-script <1.01 - XSS
Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 18, 2008
CVE-2008-1888 1 PoC Analysis EPSS 0.25
Microsoft Windows SharePoint Services 2.0 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
CWE-79 Apr 18, 2008
CVE-2008-1873 1 PoC Analysis EPSS 0.00
Nuke ET <3.2-3.4 - XSS
Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV element in the mensaje parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Apr 17, 2008