CVE & Exploit Intelligence Database

Updated 55m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
8 results Clear all
CVE-2025-25227 7.5 HIGH EPSS 0.00
Product <2FA - Auth Bypass
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CWE-287 Apr 08, 2025
CVE-2019-16725 6.1 MEDIUM EPSS 0.04
Joomla! <3.9.12 - XSS
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
CWE-79 Sep 24, 2019
CVE-2019-7743 9.8 CRITICAL EPSS 0.01
Joomla! <3.9.3 - Code Injection
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
CWE-502 Feb 12, 2019
CVE-2018-11326 4.8 MEDIUM EPSS 0.00
Joomla! < 3.8.8 - XSS
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
CWE-79 May 22, 2018
CVE-2013-5583 EPSS 0.00
Joomla! 3.1.5 - XSS
Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CWE-79 Dec 29, 2013
CVE-2011-4332 EPSS 0.00
Joomla! <1.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 23, 2011
CVE-2011-2509 EPSS 0.00
Joomla! < 1.6.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.
CWE-79 Jul 27, 2011
CVE-2010-1649 EPSS 0.00
Joomla! < 1.5.18 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.
CWE-79 Jun 08, 2010