CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
42,457 results Clear all
CVE-2008-0688 1 PoC Analysis EPSS 0.00
Smartscript Domain Trader - XSS
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.
CWE-79 Feb 12, 2008
CVE-2008-0691 1 PoC Analysis EPSS 0.01
Simon Elvery Wp-footnotes - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2) wp_footnotes_current_settings[style_rules], (3) wp_footnotes_current_settings[pre_footnotes], and (4) wp_footnotes_current_settings[post_footnotes] parameters.
CWE-79 Feb 12, 2008
CVE-2008-0679 1 PoC Analysis EPSS 0.04
Blogphp - XSS
Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Feb 12, 2008
CVE-2008-0415 EPSS 0.02
Mozilla Firefox < 2.0.0.11 - XSS
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
CWE-79 Feb 08, 2008
CVE-2008-0622 EPSS 0.00
Raidenhttpd < 2.0.19 - XSS
Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter.
CWE-79 Feb 06, 2008
CVE-2008-0617 1 PoC Analysis EPSS 0.00
Dmsguestbook - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.
CWE-79 Feb 06, 2008
CVE-2008-0618 EPSS 0.00
Dmsguestbook - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 06, 2008
CVE-2008-0605 2 PoCs Analysis EPSS 0.01
Astrosoft Helpdesk < 1.95.227 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.
CWE-79 Feb 06, 2008
CVE-2008-0576 EPSS 0.00
Drupal Project Issue Tracking Module - XSS
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages.
CWE-79 Feb 05, 2008
CVE-2008-0564 EPSS 0.02
Mailman < 2.1.10b - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.
CWE-79 Feb 05, 2008
CVE-2008-0574 1 PoC Analysis EPSS 0.00
Webspell - XSS
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.
CWE-79 Feb 05, 2008
CVE-2007-6700 1 PoC Analysis EPSS 0.05
OpenBSD 4.1 - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.
CWE-79 Feb 05, 2008
CVE-2008-0578 EPSS 0.01
Tripwire Enterprise - XSS
Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 05, 2008
CVE-2008-0179 EPSS 0.03
Liferay Enterprise Portal - XSS
Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.
CWE-79 Feb 05, 2008
CVE-2008-0181 EPSS 0.01
Liferay Enterprise Portal - XSS
Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.
CWE-79 Feb 05, 2008
CVE-2008-0180 EPSS 0.01
Liferay Enterprise Portal - XSS
Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.
CWE-79 Feb 05, 2008
CVE-2008-0178 1 PoC Analysis EPSS 0.10
Liferay Enterprise Portal - XSS
Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.
CWE-79 Feb 05, 2008
CVE-2008-0558 EPSS 0.00
Uniwin Ecart Professional - XSS
Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 04, 2008
CVE-2008-0539 1 PoC Analysis EPSS 0.02
F5 Big-ip Application Security Manager < 9.2.5 - XSS
Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.
CWE-79 Feb 01, 2008
CVE-2008-0540 2 PoCs Analysis EPSS 0.00
Trixbox - XSS
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
CWE-79 Feb 01, 2008