CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
42,457 results Clear all
CVE-2007-6486 EPSS 0.00
LineShout 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 20, 2007
CVE-2007-6477 EPSS 0.01
Citrix Web Interface <2.0 - XSS
Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 20, 2007
CVE-2007-6474 1 PoC Analysis EPSS 0.04
GF-3XPLORER 2.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.
CWE-79 Dec 20, 2007
CVE-2007-6244 2 PoCs Analysis EPSS 0.69
Adobe Flash Player <9.0.48.0,8.0.35.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
CWE-79 Dec 20, 2007
CVE-2007-6455 1 PoC Analysis EPSS 0.03
Mambo 4.6.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.
CWE-79 Dec 20, 2007
CVE-2007-6460 EPSS 0.00
Anon Proxy Server <0.101 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CVE-2007-6459.
CWE-79 Dec 20, 2007
CVE-2007-6463 EPSS 0.00
PHP Real Estate Classifieds - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes."
CWE-79 Dec 20, 2007
CVE-2007-6465 EPSS 0.01
Ganglia <3.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia before 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G, (4) me, (5) x, (6) n, (7) v, (8) l, (9) vl, and (10) st parameters to (b) web/graph.php; and the (11) c, (12) G, (13) h, (14) r, (15) m, (16) s, (17) cr, (18) hc, (19) sh, (20) p, (21) t, (22) jr, (23) js, (24) gw, (25) z, and (26) gs parameters to (c) web/get_context.php. NOTE: some of these details are obtained from third party information.
CWE-79 Dec 20, 2007
CVE-2007-6452 EPSS 0.00
Google Web Toolkit <1.4.61 - XSS
Unspecified vulnerability in the benchmark reporting system in Google Web Toolkit (GWT) before 1.4.61 has unknown impact and attack vectors, possibly related to cross-site scripting (XSS).
CWE-79 Dec 20, 2007
CVE-2007-6461 EPSS 0.00
Flyspray 0.9.9-0.9.9.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query string in an index action, related to the savesearch JavaScript function; and (2) the details parameter in a details action, related to the History tab and the getHistory JavaScript function.
CWE-79 Dec 20, 2007
CVE-2007-5854 EPSS 0.00
Apple Mac OS X <10.5.2 - XSS
Launch Services in Apple Mac OS X 10.4.11 and 10.5.1 does not treat HTML files as unsafe content, which allows attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via a crafted HTML file.
CWE-79 Dec 19, 2007
CVE-2007-5858 EPSS 0.01
WebKit - XSS
WebKit in Safari in Apple Mac OS X 10.4.11 and 10.5.1, iPhone 1.0 through 1.1.2, and iPod touch 1.1 through 1.1.2 allows remote attackers to "navigate the subframes of any other page," which can be leveraged to conduct cross-site scripting (XSS) attacks and obtain sensitive information.
CWE-79 Dec 19, 2007
CVE-2007-6407 EPSS 0.00
IBM Tivoli Provisioning Manager Express - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing."
CWE-79 Dec 17, 2007
CVE-2007-6406 EPSS 0.00
CA eTrust Threat Mgmt Console - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly Computer Associates) eTrust Threat Management Console allow remote attackers to inject arbitrary web script or HTML via the IP Address field and other unspecified fields.
CWE-79 Dec 17, 2007
CVE-2007-6367 1 PoC Analysis EPSS 0.07
SineCMS <2.3.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comment (commento) field, different vectors than CVE-2007-2357.
CWE-79 Dec 15, 2007
CVE-2007-5582 EPSS 0.01
Ciscoworks Server < 2.6 - XSS
Cross-site scripting (XSS) vulnerability in the login page in Cisco CiscoWorks Server (CS), possibly 2.6 and earlier, when using CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 15, 2007
CVE-2007-6374 2 PoCs Analysis EPSS 0.01
Bitweaver <2.0.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3) wiki/index.php or (4) forums/index.php. NOTE: the error parameter to users/login.php is covered by CVE-2006-3103.
CWE-79 Dec 15, 2007
CVE-2007-6365 EPSS 0.00
bcoos 1.0.10 - XSS
Cross-site scripting (XSS) vulnerability in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 allows remote attackers to inject arbitrary web script or HTML via the month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the day and year vectors are covered by CVE-2007-6274.
CWE-79 Dec 15, 2007
CVE-2007-6363 EPSS 0.00
IBM Tivoli Netcool Security Manager <1.3.0 - Info Disclosure
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.
CWE-79 Dec 15, 2007
CVE-2007-6364 EPSS 0.00
JLMForo System - XSS
Cross-site scripting (XSS) vulnerability in modificarPerfil.php in JLMForo System allows remote authenticated users to inject arbitrary web script or HTML via a signature.
CWE-79 Dec 15, 2007