Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-24899
7.2
HIGH
1 Writeup
NUCLEI
EPSS 0.44
Contao < 4.13.2 - XSS
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
CWE-79
May 06, 2022
CVE-2022-28080
8.8
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.42
Event Management System - SQL Injection
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
CWE-89
May 05, 2022
CVE-2022-28079
8.8
HIGH
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.71
College Management System - SQL Injection
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
CWE-89
May 05, 2022
CVE-2022-28508
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.01
MantisBT <2.25.2 - XSS
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
CWE-79
May 04, 2022
CVE-2022-24900
9.9
CRITICAL
SSVC PoC
1 Writeup
NUCLEI
EPSS 0.73
Piano Led Visualizer < 1.3 - Path Traversal
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call encounters an absolute path, it ignores all the parameters it has encountered till that point and starts working with the new absolute path. Since the "malicious" parameter represents an absolute path, the result of `os.path.join` ignores the static directory completely. Hence, untrusted input is passed via the `os.path.join` call to `flask.send_file` can lead to path traversal attacks. A patch with a fix is available on the `master` branch of the GitHub repository. This can also be fixed by preventing flow of untrusted data to the vulnerable `send_file` function. In case the application logic necessiates this behaviour, one can either use the `flask.safe_join` to join untrusted paths or replace `flask.send_file` calls with `flask.send_from_directory` calls.
CWE-22
Apr 29, 2022
CVE-2022-29081
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.88
Zoho ManageEngine <4302, <12007, <5401 - Auth Bypass
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
CWE-22
Apr 28, 2022
CVE-2022-28117
4.9
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.67
Naviwebs Navigate Cms - SSRF
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
CWE-918
Apr 28, 2022
CVE-2022-26564
6.1
MEDIUM
NUCLEI
EPSS 0.01
HotelDruid Hotel Management Software <3.0.3 - XSS
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
CWE-79
Apr 26, 2022
CVE-2022-27985
9.8
CRITICAL
NUCLEI
EPSS 0.24
Cuppacms - SQL Injection
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CWE-89
Apr 26, 2022
CVE-2022-27984
9.8
CRITICAL
NUCLEI
EPSS 0.24
Cuppacms - SQL Injection
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CWE-89
Apr 26, 2022
CVE-2022-28290
6.1
MEDIUM
NUCLEI
EPSS 0.02
Welaunch Wordpress Country Selector - XSS
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
CWE-79
Apr 25, 2022
CVE-2022-29078
9.8
CRITICAL
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.93
ejs 3.1.6 - Code Injection
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
CWE-94
Apr 25, 2022
CVE-2022-29548
4.6
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.76
Wso2 API Manager - XSS
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
CWE-79
Apr 21, 2022
CVE-2022-27926
6.1
MEDIUM
KEV
SSVC ACTIVE
NUCLEI
EPSS 0.94
Synacor Zimbra Collaboration Suite - XSS
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
CWE-79
Apr 21, 2022
CVE-2022-27924
7.5
HIGH
KEV
SSVC ACTIVE
RANSOMWARE
NUCLEI
EPSS 0.91
Synacor Zimbra Collaboration Suite - Injection
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
CWE-74
Apr 21, 2022
CVE-2022-29153
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.88
HashiCorp Consul <1.9.16-1.11.4 - SSRF
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
CWE-918
Apr 19, 2022
CVE-2022-27927
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.74
Microfinance Management System - SQL Injection
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
CWE-89
Apr 19, 2022
CVE-2022-29464
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
33 PoCs
Analysis
NUCLEI
EPSS 0.94
WSO2 Arbitrary File Upload to RCE
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
CWE-22
Apr 18, 2022
CVE-2022-25226
10.0
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.82
ThinVNC 1.0b1 - Auth Bypass
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.
Apr 18, 2022
CVE-2022-27849
5.3
MEDIUM
NUCLEI
EPSS 0.11
Plugin-planet Simple Ajax Chat < 20220115 - Information Disclosure
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
CWE-200
Apr 15, 2022