CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
42,457 results Clear all
CVE-2006-1230 1 PoC Analysis EPSS 0.01
vCard 2.x - XSS
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.
CWE-79 Mar 14, 2006
CVE-2006-0938 EPSS 0.01
EZ Publish < 3.7.3 - XSS
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.
CWE-79 Mar 01, 2006
CVE-2006-0896 EPSS 0.01
Simple Machines Forum - XSS
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.
CWE-79 Feb 25, 2006
CVE-2006-0857 1 PoC Analysis EPSS 0.00
E107 Chatbox Plugin - XSS
Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.
CWE-79 Feb 23, 2006
CVE-2006-0860 EPSS 0.01
Michael Salzer Guestbox - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular expression check, and (2) other unspecified attack vectors.
CWE-79 Feb 23, 2006
CVE-2006-0842 EPSS 0.00
Calacode Atmail Webmail System - XSS
Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by "java&#09;script:." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 22, 2006
CVE-2006-0806 1 PoC Analysis EPSS 0.13
John LIM Adodb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
CWE-79 Feb 21, 2006
CVE-2006-0800 1 PoC Analysis EPSS 0.07
Postnuke - XSS
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
CWE-79 Feb 20, 2006
CVE-2006-0779 EPSS 0.01
Xmb < 1.9.3 - XSS
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.
CWE-79 Feb 19, 2006
CVE-2006-0706 1 PoC Analysis EPSS 0.05
Gastebuch < 1.3.2 - XSS
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.
CWE-79 Feb 15, 2006
CVE-2006-0663 2 PoCs Analysis EPSS 0.01
IBM Lotus Domino Inotes Client - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java&#13;script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
CWE-79 Feb 13, 2006
CVE-2006-0603 EPSS 0.01
Hinton Design Phphg Guestbook - XSS
Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter.
CWE-79 Feb 08, 2006
CVE-2006-0533 EPSS 0.01
Cpanel - XSS
Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.
CWE-79 Feb 04, 2006
CVE-2006-0535 EPSS 0.00
Communityserver.org Community Server - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CWE-79 Feb 04, 2006
CVE-2006-0442 1 PoC Analysis EPSS 0.01
Mybb - XSS
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.
CWE-79 Jan 26, 2006
CVE-2006-0364 EPSS 0.01
Mybulletinboard - XSS
Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "&#106&#97&#118&#97&#115&#99&#114&#105&#112&#116".
CWE-79 Jan 22, 2006
CVE-2006-0233 EPSS 0.00
Microblog - XSS
Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.
CWE-79 Jan 18, 2006
CVE-2006-0208 EPSS 0.02
Php - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.
CWE-79 Jan 13, 2006
CVE-2006-0175 1 PoC Analysis EPSS 0.01
Webwiz Web Wiz Forums - XSS
Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CWE-79 Jan 11, 2006
CVE-2006-0140 EPSS 0.01
Navboard - XSS
Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.
CWE-79 Jan 09, 2006