CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
42,457 results Clear all
CVE-2006-6882 EPSS 0.00
Golden Book - XSS
Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 31, 2006
CVE-2006-7233 EPSS 0.00
Ignite Realtime Openfire < 3.5.2 - XSS
Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Dec 31, 2006
CVE-2006-4727 EPSS 0.00
Tumbleweed EMF Admin <6.3.2 - XSS
Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters.
CWE-79 Dec 31, 2006
CVE-2006-4220 1 PoC Analysis EPSS 0.01
Novell Groupwise - XSS
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
CWE-79 Dec 31, 2006
CVE-2006-6832 EPSS 0.00
Joomla! <1.0.12 - XSS
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.
CWE-79 Dec 31, 2006
CVE-2006-6824 8 PoCs Analysis EPSS 0.02
PHP iCalendar 2.23 rc1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.
CWE-79 Dec 29, 2006
CVE-2006-6746 2 PoCs Analysis EPSS 0.05
Xt-News 0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
CWE-79 Dec 27, 2006
CVE-2006-6734 1 PoC Analysis EPSS 0.01
Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c - XSS
Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter.
CWE-79 Dec 26, 2006
CVE-2006-6733 1 PoC Analysis EPSS 0.00
Support Cards 1 - XSS
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.
CWE-79 Dec 26, 2006
CVE-2006-6729 1 PoC Analysis EPSS 0.01
a-blog <1.51 - XSS
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 26, 2006
CVE-2006-6687 EPSS 0.00
WebAPP <0.9.9.4,0.9.9.3.4 NE - XSS
Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Dec 21, 2006
CVE-2006-6451 2 PoCs Analysis EPSS 0.01
SWsoft Plesk <8.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.
CWE-79 Dec 10, 2006
CVE-2006-6401 EPSS 0.01
MyStats <1.0.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter.
CWE-79 Dec 10, 2006
CVE-2006-6359 EPSS 0.01
Stefan Frech online-bookmarks 0.6.12 - XSS
Cross-site scripting (XSS) vulnerability in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 07, 2006
CVE-2006-6163 EPSS 0.00
Tikiwiki Cms/groupware < 1.9.6 - XSS
Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in TikiWiki before 1.9.7 allows remote attackers to inject arbitrary JavaScript via unspecified parameters.
CWE-79 Nov 29, 2006
CVE-2006-6162 EPSS 0.00
Tikiwiki Cms/groupware - XSS
Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Nov 29, 2006
CVE-2006-6159 EPSS 0.02
Deskpro - XSS
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or (2) subject parameter.
CWE-79 Nov 28, 2006
CVE-2006-6108 EPSS 0.01
Ec-cube - XSS
Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
CWE-79 Nov 26, 2006
CVE-2006-6096 1 PoC Analysis EPSS 0.03
Dotnetindex Active News Manager - XSS
Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.
CWE-79 Nov 24, 2006
CVE-2006-6037 EPSS 0.02
Leinir Travelsized Cms < 0.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dan Jensen Travelsized CMS 0.4.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) page, (2) page_id, or (3) language parameter.
CWE-79 Nov 22, 2006