CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
42,457 results Clear all
CVE-2007-6695 EPSS 0.00
Drake CMS 0.4.9 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Drake CMS 0.4.9 allows remote attackers to inject arbitrary web script or HTML via the option parameter.
CWE-79 Feb 01, 2008
CVE-2008-0547 1 PoC Analysis EPSS 0.06
Shoppingtree Candypress Store - XSS
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.
CWE-79 Feb 01, 2008
CVE-2008-0552 1 PoC Analysis EPSS 0.06
Eticket - XSS
Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Feb 01, 2008
CVE-2008-0541 1 PoC Analysis EPSS 0.03
Gerd Tentler Simple Forum - XSS
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.
CWE-79 Feb 01, 2008
CVE-2007-6696 2 PoCs Analysis EPSS 0.00
WebCalendar 1.1.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication.
CWE-79 Feb 01, 2008
CVE-2008-0505 EPSS 0.01
Coppermine Photo Gallery < 1.4.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.
CWE-79 Jan 31, 2008
CVE-2008-0523 EPSS 0.00
Softcart - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SoftCart.exe in SoftCart 5.1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) License_Plate, (2) License_State, (3) Ticket_Date, and (4) Ticket_Number parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 31, 2008
CVE-2008-0522 EPSS 0.01
HAL Networks Perl Cgi Cart - XSS
Cross-site scripting (XSS) vulnerability in multiple Hal Networks shopping-cart products allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 31, 2008
CVE-2008-0494 EPSS 0.00
Endian Firewall - XSS
Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 30, 2008
CVE-2008-0497 1 PoC Analysis EPSS 0.01
Nucleus Cms - XSS
Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.
CWE-79 Jan 30, 2008
CVE-2008-0496 1 PoC Analysis EPSS 0.01
Ampjuke - XSS
Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action.
CWE-79 Jan 30, 2008
CVE-2008-0474 1 PoC Analysis EPSS 0.00
Manageengine Applications Manager - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 29, 2008
CVE-2008-0409 EPSS 0.01
HFS HTTP File Server < 2.2b - XSS
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
CWE-79 Jan 29, 2008
CVE-2008-0463 EPSS 0.00
Drupal Workflow < 4.7.x-1.1 - XSS
Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.
CWE-79 Jan 25, 2008
CVE-2008-0460 EPSS 0.16
Mediawiki - XSS
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 25, 2008
CVE-2008-0462 EPSS 0.00
Drupal Archive Module < 5_1.7 - XSS
Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 25, 2008
CVE-2008-0454 EPSS 0.44
Microsoft Internet Explorer < 3.6.0.244 - XSS
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."
CWE-79 Jan 25, 2008
CVE-2008-0455 1 PoC Analysis EPSS 0.52
Apache HTTP Server < 2.2.23 - XSS
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
CWE-79 Jan 25, 2008
CVE-2008-0444 EPSS 0.00
Elog - XSS
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
CWE-79 Jan 25, 2008
CVE-2008-0426 EPSS 0.00
Pacercms < 0.6.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text field in a message.
CWE-79 Jan 23, 2008