CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
42,457 results Clear all
CVE-2007-4862 1 PoC Analysis EPSS 0.03
Quirm Saxon - XSS
Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter.
CWE-79 Oct 30, 2007
CVE-2007-5727 EPSS 0.01
Oneorzero Helpdesk - XSS
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
CWE-79 Oct 30, 2007
CVE-2007-5728 1 PoC Analysis NUCLEI EPSS 0.01
Phppgadmin - XSS
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.
CWE-79 Oct 30, 2007
CVE-2007-5725 1 PoC Analysis EPSS 0.01
Smart-shop - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script or HTML via (1) the email parameter to index.php; or the command parameter to index.php in (2) the default action for the home page, (3) a currencies action, or (4) a basket action.
CWE-79 Oct 30, 2007
CVE-2007-5710 1 PoC Analysis EPSS 0.03
Wordpress - XSS
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
CWE-79 Oct 30, 2007
CVE-2007-4348 EPSS 0.00
IBM TSM Client <5.4.1.2 - XSS
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
CWE-79 Oct 30, 2007
CVE-2007-5703 EPSS 0.04
RSA Keon Registration Authority Web Interface - XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 29, 2007
CVE-2007-5702 EPSS 0.01
Novell Opensuse Swamp - XSS
Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 29, 2007
CVE-2007-5698 EPSS 0.00
Creapark Gold Koy Portali - XSS
Cross-site scripting (XSS) vulnerability in default.asp in CREApark GOLD KOY PORTALI allows remote attackers to inject arbitrary web script or HTML via the aranan parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 29, 2007
CVE-2007-5692 3 PoCs Analysis EPSS 0.06
Sitebar - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter in a Folder Properties action, or (4) the uid parameter in a Modify User action to command.php; or (5) the target parameter to index.php, different vectors than CVE-2006-3320.
CWE-79 Oct 29, 2007
CVE-2007-5683 EPSS 0.00
Tikiwiki Cms/groupware < 1.9.8.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.
CWE-79 Oct 26, 2007
CVE-2007-5677 1 PoC Analysis EPSS 0.01
Hackish - XSS
Cross-site scripting (XSS) vulnerability in shoutbox/blocco.php in Hackish BETA 1.1 allows remote attackers to inject arbitrary web script or HTML via the go_shout parameter.
CWE-79 Oct 24, 2007
CVE-2007-5673 EPSS 0.00
Ifnet Webif - XSS
Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet WebIf allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.
CWE-79 Oct 24, 2007
CVE-2007-5647 1 PoC Analysis EPSS 0.02
Socketkb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) art_id or (2) node parameter in an article action to the default URI.
CWE-79 Oct 23, 2007
CVE-2007-5649 1 PoC Analysis EPSS 0.02
Socketmail - XSS
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.
CWE-79 Oct 23, 2007
CVE-2007-5648 1 PoC Analysis EPSS 0.01
Rnote - XSS
Multiple cross-site scripting (XSS) vulnerabilities in rnote.php in rNote 0.9.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) d or the (2) u parameter.
CWE-79 Oct 23, 2007
CVE-2007-5625 1 PoC Analysis EPSS 0.06
Simongibson Asp Site Search Searchsimon Lite - XSS
Cross-site scripting (XSS) vulnerability in filename.asp in ASP Site Search SearchSimon Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.
CWE-79 Oct 23, 2007
CVE-2007-5624 EPSS 0.00
Nagios < 2.9 - XSS
Cross-site scripting (XSS) vulnerability in Nagios 2.x before 2.10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts.
CWE-79 Oct 23, 2007
CVE-2007-5629 EPSS 0.01
Candypress Store - XSS
Cross-site scripting (XSS) vulnerability in admin/logon.asp in ShoppingTree CandyPress Store 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2007-2804. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Oct 23, 2007
CVE-2007-5472 EPSS 0.01
Broadcom Host-based Intrusion Prevention System < 8 - XSS
Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer.
CWE-79 Oct 22, 2007