CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
42,457 results Clear all
CVE-2007-5428 1 PoC Analysis EPSS 0.02
Umi-cms Umi Cms - XSS
Cross-site scripting (XSS) vulnerability in UMI CMS allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to the default URI in search_do/.
CWE-79 Oct 12, 2007
CVE-2007-5433 EPSS 0.01
Siteup - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Site-Up 2.64 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) search mask field.
CWE-79 Oct 12, 2007
CVE-2007-5429 1 PoC Analysis EPSS 0.01
Nucleus Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter.
CWE-79 Oct 12, 2007
CVE-2007-5415 EPSS 0.00
Mozilla Firefox - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.
CWE-79 Oct 12, 2007
CVE-2007-5414 EPSS 0.00
Mozilla Firefox < 1.8 - XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.
CWE-79 Oct 12, 2007
CVE-2007-5411 1 PoC Analysis EPSS 0.02
Linksys Spa941 - XSS
Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.
CWE-79 Oct 12, 2007
CVE-2007-5386 1 PoC Analysis EPSS 0.11
Phpmyadmin - XSS
Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.
CWE-79 Oct 12, 2007
CVE-2007-5385 EPSS 0.00
Alcatel Speedtouch 7G Router - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 12, 2007
CVE-2007-5370 1 PoC Analysis EPSS 0.01
Netwin Dnewsweb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.
CWE-79 Oct 11, 2007
CVE-2007-5312 1 PoC Analysis EPSS 0.10
Torrenttrader - XSS
Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat parameter to browse.php.
CWE-79 Oct 09, 2007
CVE-2007-5303 EPSS 0.00
Snewscms Rus - XSS
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.
CWE-79 Oct 09, 2007
CVE-2007-5290 2 PoCs Analysis EPSS 0.02
Afterlogic Mailbee Webmail - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to login.php and the (2) mode2 parameter to default.asp in an advanced_login mode.
CWE-79 Oct 09, 2007
CVE-2007-5304 1 PoC Analysis EPSS 0.05
Yannick Tanguy Else IF Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3) elseifforumtxtmenugeneraleduforum parameter to moduleajouter/depot/adminforum.php.
CWE-79 Oct 09, 2007
CVE-2007-5296 EPSS 0.00
Livio Siri Dblist - XSS
Multiple cross-site scripting (XSS) vulnerabilities in dblisttest.asp in dbList 8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) db, (2) pagesize, (3) sort, (4) strKeyWords, and (5) table parameters. NOTE: some of these details are obtained from third party information.
CWE-79 Oct 09, 2007
CVE-2007-5302 EPSS 0.01
Hp-ux - XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 09, 2007
CVE-2007-5297 EPSS 0.01
Minki - XSS
Cross-site scripting (XSS) vulnerability in index.php in Minki 1.30 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Oct 09, 2007
CVE-2007-5292 EPSS 0.00
Splitside Directory Image Gallery - XSS
Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter.
CWE-79 Oct 09, 2007
CVE-2007-5293 1 PoC Analysis EPSS 0.09
Idmos - XSS
Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php.
CWE-79 Oct 09, 2007
CVE-2007-5291 EPSS 0.00
Daniel Broadbent DB Manager - XSS
Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79 Oct 09, 2007
CVE-2007-5295 EPSS 0.00
Wikepage Opus - Code Injection
Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters.
CWE-94 Oct 09, 2007