CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
42,457 results Clear all
CVE-2008-1025 EPSS 0.01
Apple Safari - XSS
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
CWE-79 Apr 17, 2008
CVE-2008-1846 EPSS 0.01
SAP NetWeaver <7.0 SP15 - XSS
The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
CWE-79 Apr 16, 2008
CVE-2008-1850 EPSS 0.00
Omnistar Interactive OSI Affiliate - XSS
Multiple cross-site scripting (XSS) vulnerabilities in login.php in Omnistar Interactive OSI Affiliate allow remote attackers to inject arbitrary web script or HTML via the (1) login, (2) profile, (3) profile2, and (4) ref parameters.
CWE-79 Apr 16, 2008
CVE-2008-1839 EPSS 0.00
WORK system e-commerce 4.0.9 - XSS
Multgiple cross-site scripting (XSS) vulnerabilities in module/main.php in WORK system e-commerce 4.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, and (3) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 16, 2008
CVE-2008-1848 1 PoC Analysis EPSS 0.03
JoomlaXplorer <1.6.2 - XSS
Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php.
CWE-79 Apr 16, 2008
CVE-2008-1800 1 PoC Analysis EPSS 0.00
DivXDB 2000.94b - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML via the (1) choice, (2) _page_, (3) zone_admin, (4) general_search, and (5) import parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 15, 2008
CVE-2008-1794 EPSS 0.00
Drupal Webform <5.x-1.10, <5.x-2.0-beta3, <6.x-1.0-beta3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Webform Drupal module 5.x before 5.x-1.10, 5.x-2.x before 5.x-2.0-beta3, and 6.x before 6.x-1.0-beta3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 15, 2008
CVE-2008-1793 EPSS 0.00
Hoffice Smart Classified Ads - XSS
Multiple cross-site scripting (XSS) vulnerabilities in view.cgi in Smart Classified ADS Professional, Smart Photo ADS, and Smart Photo ADS Gold allow remote attackers to inject arbitrary web script or HTML via the (1) AdNum and (2) Department parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 15, 2008
CVE-2008-1795 2 PoCs Analysis EPSS 0.11
Blackboard Academic Suite <8.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to webapps/blackboard/execute/viewCatalog or (2) the data__announcements___pk1_pk2__subject parameter in an ADD action to bin/common/announcement.pl.
CWE-79 Apr 15, 2008
CVE-2008-1787 1 PoC Analysis EPSS 0.00
Poplar Gedcom Viewer 2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Poplar Gedcom Viewer 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) text and (2) ul parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 15, 2008
CVE-2008-1792 EPSS 0.00
Flickr Drupal <5.x-1.3,6.x-1.0-alpha - XSS
Cross-site scripting (XSS) vulnerability in the insertion filter in the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-alpha allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 15, 2008
CVE-2008-1775 EPSS 0.00
ManageEngine Firewall Analyzer 4.0.3 - XSS
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 14, 2008
CVE-2008-1757 1 PoC Analysis EPSS 0.00
KwsPHP 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the VIEW parameter.
CWE-79 Apr 12, 2008
CVE-2008-1753 EPSS 0.00
Alkacon OpenCMS 7.0.3 - XSS
Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a different vector than CVE-2008-1510.
CWE-79 Apr 11, 2008
CVE-2008-1655 EPSS 0.27
Adobe Flash Player <9.0.115.0 - SSRF
Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.
CWE-79 Apr 09, 2008
CVE-2008-1716 EPSS 0.00
WoltLab Community Framework <1.0.6 - XSS
Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message.
CWE-79 Apr 09, 2008
CVE-2008-1698 EPSS 0.00
Simple Gallery 2.2 - XSS
Cross-site scripting (XSS) vulnerability in gallery.php in Simple Gallery 2.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 08, 2008
CVE-2008-1649 1 PoC Analysis EPSS 0.09
EasyNews 4.0 - XSS
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.
CWE-79 Apr 02, 2008
CVE-2008-1634 EPSS 0.00
JV2 Folder Gallery 3.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in JV2 Folder Gallery 3.1 allows remote attackers to inject arbitrary web script or HTML via the image parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 02, 2008
CVE-2008-1621 3 PoCs Analysis EPSS 0.00
GeeCarts - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Apr 02, 2008