CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
42,457 results Clear all
CVE-2007-6232 2 PoCs Analysis EPSS 0.03
FTP Admin 0.1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
CWE-79 Dec 04, 2007
CVE-2007-6219 EPSS 0.00
IBM Tivoli Netcool Security Manager 1.3.0 - XSS
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 04, 2007
CVE-2007-6203 1 PoC Analysis EPSS 0.73
Apache HTTP Server 2.0.x-2.2.x - XSS
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
CWE-79 Dec 03, 2007
CVE-2007-6196 EPSS 0.01
Calacode @Mail <5.2 - XSS
Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.
CWE-79 Dec 01, 2007
CVE-2007-6173 1 PoC Analysis EPSS 0.08
Liferay Enterprise Portal 4.3.1 - XSS
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress parameter in a Send New Password action, a different vector than CVE-2007-6055. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 30, 2007
CVE-2007-6162 1 PoC Analysis EPSS 0.00
FMDeluxe 2.1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.
CWE-79 Nov 29, 2007
CVE-2007-6157 1 PoC Analysis EPSS 0.01
SimpleGallery 0.1.3 - XSS
Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
CWE-79 Nov 29, 2007
CVE-2007-6156 EPSS 0.01
Base Analysis and Security Engine <1.3.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[0] and (2) sig[1] parameters.
CWE-79 Nov 29, 2007
CVE-2007-6160 1 PoC Analysis EPSS 0.02
Tilde CMS <4 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a yeardetail action.
CWE-79 Nov 29, 2007
CVE-2007-6135 1 PoC Analysis EPSS 0.08
PHPSlideShow 0.9.9.2 - XSS
Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file.
CWE-79 Nov 27, 2007
CVE-2007-6136 1 PoC Analysis EPSS 0.00
M2Scripts MySpace Scripts Poll Creator - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details are obtained from third party information.
CWE-79 Nov 27, 2007
CVE-2007-6141 1 PoC Analysis EPSS 0.00
vBTube 1.1 Beta - XSS
Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Nov 27, 2007
CVE-2007-6142 EPSS 0.00
ph03y3nk JAF CMS 4.0 RC2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 27, 2007
CVE-2007-6126 1 PoC Analysis EPSS 0.04
Project Alumni <1.0.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.
CWE-79 Nov 26, 2007
CVE-2007-6124 1 PoC Analysis EPSS 0.04
Softbiz Freelancers Script - XSS
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.
CWE-79 Nov 26, 2007
CVE-2007-6104 EPSS 0.01
FileMaker Pro <8 - XSS
Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 23, 2007
CVE-2007-6110 1 PoC Analysis EPSS 0.07
htdig 3.2.0b6 - XSS
Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.
CWE-79 Nov 23, 2007
CVE-2007-6102 EPSS 0.01
Feed to JavaScript 1.91 - XSS
Cross-site scripting (XSS) vulnerability in Feed to JavaScript (Feed2JS) 1.91 allows remote attackers to inject arbitrary web script or HTML via a URL in a feed.
CWE-79 Nov 23, 2007
CVE-2007-6100 EPSS 0.01
phpMyAdmin <2.11.2.2 - XSS
Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.
CWE-79 Nov 23, 2007
CVE-2007-6090 EPSS 0.00
Nuked-Klan 1.7.5 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 22, 2007