CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
42,457 results Clear all
CVE-2008-0438 1 PoC Analysis EPSS 0.11
Novemberborn Sifr - XSS
Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.
CWE-79 Jan 23, 2008
CVE-2008-0439 1 PoC Analysis EPSS 0.02
Deluxebb - XSS
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.
CWE-79 Jan 23, 2008
CVE-2008-0432 1 PoC Analysis EPSS 0.00
Agares Media Phpautovideo < 2.21 - XSS
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
CWE-79 Jan 23, 2008
CVE-2008-0436 1 PoC Analysis EPSS 0.01
PD9 Software Megabbs - XSS
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.
CWE-79 Jan 23, 2008
CVE-2008-0400 1 PoC Analysis EPSS 0.00
Modern - XSS
Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.
CWE-79 Jan 23, 2008
CVE-2008-0398 1 PoC Analysis EPSS 0.03
Aflog < 1.01 - XSS
Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.
CWE-79 Jan 23, 2008
CVE-2008-0404 EPSS 0.01
Mantis < 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.
CWE-79 Jan 23, 2008
CVE-2008-0381 EPSS 0.00
Mahara < 0.9.0 - XSS
Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.
CWE-79 Jan 22, 2008
CVE-2008-0370 EPSS 0.00
Cpanel - XSS
Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 22, 2008
CVE-2008-0362 EPSS 0.00
Clever Copy < 3.0 - XSS
Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.
CWE-79 Jan 18, 2008
CVE-2008-0354 EPSS 0.01
IBM Lotus Sametime - XSS
Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.
CWE-79 Jan 18, 2008
CVE-2008-0359 1 PoC Analysis EPSS 0.07
Blog Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.
CWE-79 Jan 18, 2008
CVE-2008-0334 1 PoC Analysis EPSS 0.00
Pmachine Pro - XSS
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.
CWE-79 Jan 17, 2008
CVE-2008-0335 EPSS 0.00
Bugtracker.net < 2.7.1 - XSS
Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.
CWE-79 Jan 17, 2008
CVE-2007-6687 EPSS 0.01
Menalto Gallery <2.2.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP PROPPATCH in the WebDAV module.
CWE-79 Jan 17, 2008
CVE-2008-0292 EPSS 0.00
Dansie Photo Album - XSS
Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 16, 2008
CVE-2008-0284 EPSS 0.00
Simple Machines Smf < 1.1.4 - XSS
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.
CWE-79 Jan 15, 2008
CVE-2008-0258 1 PoC Analysis EPSS 0.01
PHP Running Management Phprunman < 1.0.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CWE-79 Jan 15, 2008
CVE-2008-0257 EPSS 0.00
Dansie Search Engine - XSS
Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 15, 2008
CVE-2008-0268 1 PoC Analysis EPSS 0.02
Eticket - XSS
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
CWE-79 Jan 15, 2008