Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,490 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,201 vendors 42,812 researchers
42,624 results Clear all
CVE-2003-1384 EPSS 0.01
PY Software Py-livredor - XSS
Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.
CWE-79 Dec 31, 2003
CVE-2003-1353 EPSS 0.00
Lanifex Outreach Project Tool - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.
CWE-79 Dec 31, 2003
CVE-2003-1546 EPSS 0.00
Filebased Guestbook - XSS
Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.
CWE-79 Dec 31, 2003
CVE-2003-1543 EPSS 0.00
Bajie Java HTTP Server - XSS
Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.
CWE-79 Dec 31, 2003
CVE-2003-0624 1 PoC Analysis EPSS 0.03
BEA WebLogic <8.1 - XSS
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
CWE-79 Dec 01, 2003
CVE-2003-0712 EPSS 0.18
Microsoft Exchange Server 5.5 OWA - XSS
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.
CWE-79 Nov 17, 2003
CVE-2003-1151 1 PoC Analysis EPSS 0.01
Fastream NETFile Server 6.0.3.588 - XSS
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.
CWE-79 Oct 28, 2003
CVE-2003-0801 1 PoC Analysis EPSS 0.00
Nokia Electronic Documentation <5.0 - XSS
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.
CWE-79 Oct 06, 2003
CVE-2003-0310 1 PoC Analysis EPSS 0.00
eZ publish 2.2 - XSS
Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.
CWE-79 Jun 16, 2003
CVE-2002-2362 1 PoC Analysis EPSS 0.01
Sourceforge Mymarket - XSS
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.
CWE-79 Dec 31, 2002
CVE-2002-2321 1 PoC Analysis EPSS 0.01
Phplinkat - XSS
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
CWE-79 Dec 31, 2002
CVE-2002-2377 EPSS 0.00
Sephiroth32 Zap Book - XSS
Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.
CWE-79 Dec 31, 2002
CVE-2002-1958 1 PoC Analysis EPSS 0.01
Kmmail - XSS
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.
CWE-79 Dec 31, 2002
CVE-2002-1651 EPSS 0.02
Verity Search97 - XSS
Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.
CWE-79 Dec 31, 2002
CVE-2002-2386 EPSS 0.00
Xoops - XSS
Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS 1.0, when allowing on-line question development, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the SRC attribute of an IMG tag.
CWE-79 Dec 31, 2002
CVE-2002-2350 EPSS 0.00
Phpoutsourcing Zorum - XSS
Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web script or HTML via the class parameter.
CWE-79 Dec 31, 2002
CVE-2002-2341 1 PoC Analysis EPSS 0.00
Sonicwall Soho3 - XSS
Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML via a blocked URL.
CWE-79 Dec 31, 2002
CVE-2002-2330 EPSS 0.00
Uninet Statsplus - XSS
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.
CWE-79 Dec 31, 2002
CVE-2002-1700 1 PoC Analysis EPSS 0.16
Macromedia Coldfusion - XSS
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
CWE-79 Dec 31, 2002
CVE-2002-1852 1 PoC Analysis EPSS 0.03
Monkey - XSS
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.
CWE-79 Dec 31, 2002