CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,280 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,569 researchers
42,457 results Clear all
CVE-2007-6677 EPSS 0.00
Peter's Random Anti-Spam Image <0.2.4 - XSS
Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.
CWE-79 Jan 10, 2008
CVE-2008-0205 EPSS 0.00
Wordpress Math Comment Spam Protection Plugin < 2.1 - XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.
CWE-79 Jan 10, 2008
CVE-2008-0186 1 PoC Analysis EPSS 0.03
Phprisk Netrisk < 1.9.7 - XSS
Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.
CWE-79 Jan 09, 2008
CVE-2007-5403 EPSS 0.00
Layton Technology Helpbox - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6) sys_request_id parameter to requestattach.asp; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) Asset, (8) Location, and (9) Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset Location, (12) Problem Desc, and (13) Solution Desc fields to editrequestuser.asp; and the (14) End User and (15) Description fields to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require authentication to exploit.
CWE-79 Jan 09, 2008
CVE-2008-0155 1 PoC Analysis EPSS 0.02
Evilboard - XSS
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.
CWE-79 Jan 09, 2008
CVE-2007-6674 EPSS 0.00
RapidShare Database - XSS
Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.
CWE-79 Jan 08, 2008
CVE-2008-0134 EPSS 0.00
Snitz Communications Snitz Forums 2000 < 3.4.06 - XSS
Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.
CWE-79 Jan 08, 2008
CVE-2007-6421 EPSS 0.03
Apache HTTP Server <2.2.7 - XSS
Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
CWE-79 Jan 08, 2008
CVE-2008-0146 1 PoC Analysis EPSS 0.01
Hughes Technologies W3-msql - XSS
Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.
CWE-79 Jan 08, 2008
CVE-2007-6388 EPSS 0.87
Apache HTTP Server <2.2.7-2.0.62-1.3.40 - XSS
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 08, 2008
CVE-2007-6673 1 PoC Analysis EPSS 0.02
Makale Scripti - XSS
Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action.
CWE-79 Jan 08, 2008
CVE-2008-0131 EPSS 0.00
Instantsoftwares Dating Site - XSS
Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jan 08, 2008
CVE-2007-6669 1 PoC Analysis EPSS 0.02
PHCDownload 1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter.
CWE-79 Jan 08, 2008
CVE-2008-0093 EPSS 0.00
Eticket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.
CWE-79 Jan 08, 2008
CVE-2007-6659 EPSS 0.00
2z project 0.9.6.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in 2z project 0.9.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) contentshort or (2) contentfull parameter in an addnews action to the default URI; (3) the content parameter in a pm write action to 2z/admin.php; (4) the referer parameter to templates/default/usermenu.tpl, accessed through index.php; or the (5) newavatar or (6) newphoto parameter in a profile action to the default URI under 2z/.
CWE-79 Jan 04, 2008
CVE-2007-6641 1 PoC Analysis EPSS 0.02
milliscripts Redirection - XSS
Cross-site scripting (XSS) vulnerability in dir.php in milliscripts Redirection allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a browse action.
CWE-79 Jan 04, 2008
CVE-2008-0092 1 PoC Analysis EPSS 0.04
Phpwebsite - XSS
Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Jan 04, 2008
CVE-2007-6646 4 PoCs Analysis EPSS 0.01
LiveCart <1.1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword, (2) the q parameter to the category script, (3) the return parameter to the order script, or (4) the email parameter to user/remindComplete.
CWE-79 Jan 04, 2008
CVE-2007-6643 EPSS 0.00
Joomla! <1.5 RC4 - XSS
Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla! before 1.5 RC4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 04, 2008
CVE-2007-6637 EPSS 0.45
Adobe Flash Player - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.
CWE-79 Jan 04, 2008