CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
42,457 results Clear all
CVE-2007-2801 1 PoC Analysis EPSS 0.09
eTicket <1.5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."
CWE-79 Jun 30, 2007
CVE-2007-3503 EPSS 0.01
Oracle Jdk - XSS
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jun 30, 2007
CVE-2007-3484 6.1 MEDIUM EPSS 0.01
Google Custom Search Engine - XSS
Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this issue is disputed by the Google Security Team, who states that "Google does not provide the 'search.php' script referenced. When a user creates a custom search engine, we provide them with a block of javascript to include on their site. Some users write additional code around this block of javascript to further customize their website.
CWE-79 Jun 28, 2007
CVE-2007-3482 EPSS 0.00
Apple Safari - XSS
Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the "same origin policy" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute.
CWE-79 Jun 28, 2007
CVE-2007-3448 1 PoC Analysis EPSS 0.08
Bugmall Shopping Cart - XSS
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
CWE-79 Jun 27, 2007
CVE-2007-3405 EPSS 0.00
Lebisoft Zdefter - XSS
Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ad and (2) konu parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Jun 26, 2007
CVE-2007-2400 EPSS 0.00
Apple Safari <3.0.2 - XSS
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
CWE-362 Jun 25, 2007
CVE-2007-2401 1 PoC Analysis EPSS 0.03
Apple Mac OS X <10.4.9 - CRLF Injection
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
CWE-79 Jun 25, 2007
CVE-2007-3339 3 PoCs Analysis EPSS 0.04
Fusetalk - XSS
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.
CWE-79 Jun 21, 2007
CVE-2007-3291 1 PoC Analysis EPSS 0.04
Livecms - XSS
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.
CWE-79 Jun 20, 2007
CVE-2007-3227 1 PoC Analysis EPSS 0.14
Rails < 1.2.5 - XSS
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
CWE-79 Jun 14, 2007
CVE-2007-2450 EPSS 0.01
Apache Tomcat <6.0.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
CWE-79 Jun 14, 2007
CVE-2007-2391 EPSS 0.01
Apple Safari Beta 3.0.1 - XSS
Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.
CWE-79 Jun 14, 2007
CVE-2007-3156 EPSS 0.01
Webmin Usermin < 1.280 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.
CWE-79 Jun 11, 2007
CVE-2007-3137 2 PoCs Analysis EPSS 0.05
Webmaster Solutions Wmscms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.
CWE-79 Jun 08, 2007
CVE-2007-3064 1 PoC Analysis EPSS 0.01
Mealex MY Datebook - XSS
Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.
CWE-79 Jun 06, 2007
CVE-2007-3056 EPSS 0.01
Websvn < 2.0rc4 - XSS
Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path parameter.
CWE-79 Jun 06, 2007
CVE-2007-3008 EPSS 0.01
Mbedthis Software Mbedthis Appweb HTTP Server - Information Disclosure
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
CWE-79 Jun 04, 2007
CVE-2007-2914 EPSS 0.01
PsychoStats 3.0.6b - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php, (4) weapons.php, and possibly other unspecified files.
CWE-79 May 30, 2007
CVE-2007-2910 EPSS 0.00
Jelsoft vBulletin <3.6.7 PL1 - XSS
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a related issue to CVE-2007-2909.
CWE-79 May 30, 2007