CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
42,457 results Clear all
CVE-2007-6633 1 PoC Analysis EPSS 0.02
FAQMasterFlexPlus <1.52 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to inject arbitrary web script or HTML via (1) the cat_name parameter to faq.php; and unspecified parameters to the (2) add categories, (3) edit categories, (4) delete categories, (5) add faq, (6) edit faq, and (7) delete faq Admin scripts.
CWE-79 Jan 04, 2008
CVE-2007-6616 EPSS 0.00
SimpleForum <4.6.2 - XSS
Cross-site scripting (XSS) vulnerability in simpleforum.cgi in SimpleForum 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchkey parameter in a search action. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 03, 2008
CVE-2007-6617 EPSS 0.00
JIRA Enterprise Edition <3.12.1 - XSS
Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.
CWE-79 Jan 03, 2008
CVE-2007-6611 EPSS 0.01
Mantis <1.1.0 - XSS
Cross-site scripting (XSS) vulnerability in view.php in Mantis before 1.1.0 allows remote attackers to inject arbitrary web script or HTML via a filename, related to bug_report.php.
CWE-79 Jan 03, 2008
CVE-2007-6608 3 PoCs Analysis EPSS 0.02
OpenBiblio <0.5.2-pre4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIRST parameters to admin/staff_del_confirm.php, (3) the name parameter to admin/theme_del_confirm.php, or (4) the themeName parameter to admin/theme_preview.php.
CWE-79 Dec 31, 2007
CVE-2007-6597 2 PoCs Analysis EPSS 0.04
IPortalX <Build 033 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and (3) the Date parameter to blogs.asp.
CWE-79 Dec 31, 2007
CVE-2007-6569 EPSS 0.01
Sun Java System Web Proxy Server <4.0.6 - XSS
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
CWE-79 Dec 28, 2007
CVE-2007-6570 EPSS 0.01
Sun Java System Web Proxy Server <4.0.6 & <3.6 - XSS
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
CWE-79 Dec 28, 2007
CVE-2007-6574 3 PoCs Analysis EPSS 0.01
Dokeos <1.8.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.
CWE-79 Dec 28, 2007
CVE-2007-6589 EPSS 0.01
Mozilla Firefox <2.0.0.10 & SeaMonkey <1.1.7 - XSS
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.
CWE-79 Dec 28, 2007
CVE-2007-6588 EPSS 0.00
PHCDownload 1.10 - XSS
Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows remote attackers to inject arbitrary web script or HTML via the username field in an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Dec 28, 2007
CVE-2007-6571 EPSS 0.00
Sun Java System Web Proxy Server <3.6 - XSS
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
CWE-79 Dec 28, 2007
CVE-2007-6572 EPSS 0.00
Sun Java System Web Server <7.0 - XSS
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.
CWE-79 Dec 28, 2007
CVE-2007-6564 1 PoC Analysis EPSS 0.03
Limbo CMS 1.0.4.2 - XSS
Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter.
CWE-79 Dec 28, 2007
CVE-2007-6545 1 PoC Analysis EPSS 0.08
RunCMS <1.6.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.
CWE-79 Dec 28, 2007
CVE-2007-6560 2 PoCs Analysis EPSS 0.01
Logaholic <2.0 RC8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
CWE-79 Dec 28, 2007
CVE-2007-6541 EPSS 0.00
Neuron News 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.
CWE-79 Dec 27, 2007
CVE-2007-6526 EPSS 0.01
TikiWiki <1.9.9 - XSS
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.
CWE-79 Dec 27, 2007
CVE-2007-6522 EPSS 0.01
Opera <9.25 - XSS
The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains.
CWE-79 Dec 24, 2007
CVE-2007-6520 EPSS 0.01
Opera <9.25 - XSS
Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins.
CWE-79 Dec 24, 2007