Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-27043 7.5 HIGH NUCLEI EPSS 0.26
Yearning < 2.3.6 - Path Traversal
Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.
CWE-22 Apr 15, 2022
CVE-2022-24816 10.0 CRITICAL KEV SSVC ACTIVE 1 PoC Analysis NUCLEI EPSS 0.94
Geosolutionsgroup Jai-ext < 1.1.22 - Code Injection
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.
CWE-94 Apr 13, 2022
CVE-2022-28033 9.8 CRITICAL NUCLEI EPSS 0.58
Thedigitalcraft Atomcms - SQL Injection
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
CWE-89 Apr 12, 2022
CVE-2022-28032 9.8 CRITICAL NUCLEI EPSS 0.47
Thedigitalcraft Atomcms - SQL Injection
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
CWE-89 Apr 12, 2022
CVE-2022-28365 5.3 MEDIUM EXPLOITED NUCLEI EPSS 0.56
Reprise License Manager 14.2 - Info Disclosure
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
CWE-425 Apr 09, 2022
CVE-2022-28363 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.05
Reprise License Manager 14.2 - XSS
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
CWE-79 Apr 09, 2022
CVE-2022-24819 5.3 MEDIUM SSVC PoC NUCLEI EPSS 0.04
XWiki Platform - Info Disclosure
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.
CWE-359 Apr 08, 2022
CVE-2022-24681 6.1 MEDIUM NUCLEI EPSS 0.23
Zoho ManageEngine ADSelfService Plus <6.12.1 - XSS
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
CWE-79 Apr 07, 2022
CVE-2022-28219 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.94
ManageEngine ADAudit Plus CVE-2022-28219
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CWE-611 Apr 05, 2022
CVE-2022-25356 5.3 MEDIUM SSVC PoC NUCLEI EPSS 0.73
Alt-N MDaemon Security Gateway <8.5.0 - XML Injection
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
CWE-91 Apr 05, 2022
CVE-2022-26585 9.8 CRITICAL 1 PoC NUCLEI EPSS 0.48
Mingsoft MCMS <5.2.7 - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CWE-89 Apr 05, 2022
CVE-2022-26233 7.5 HIGH NUCLEI EPSS 0.70
Barco Control Room Management <2.9 Build 0275 - Path Traversal
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
CWE-22 Apr 03, 2022
CVE-2022-24181 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.04
PKP Open Journals System >=2.4.8 - XSS
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
CWE-79 Apr 01, 2022
CVE-2022-26271 7.5 HIGH NUCLEI EPSS 0.13
74cmsSE v3.4.1 - Info Disclosure
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
CWE-552 Mar 28, 2022
CVE-2022-26263 6.1 MEDIUM NUCLEI EPSS 0.10
Yonyou u8 <13.0 - XSS
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
CWE-79 Mar 25, 2022
CVE-2022-25568 7.5 HIGH NUCLEI EPSS 0.85
MotionEye Config Info Disclosure
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
CWE-1188 Mar 24, 2022
CVE-2022-23881 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.87
ZZZCMS zzzphp <2.1.0 - RCE
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
Mar 23, 2022
CVE-2022-27228 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.92
Bitrix24 < 21.0.100 - Improper Input Validation
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
CWE-20 Mar 22, 2022
CVE-2022-26148 9.8 CRITICAL NUCLEI EPSS 0.90
Grafana & Zabbix Integration - Credentials Disclosure
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.
CWE-312 Mar 21, 2022
CVE-2022-23348 5.3 MEDIUM 1 Writeup NUCLEI EPSS 0.01
BigAnt Server <5.6.06 - Info Disclosure
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CWE-916 Mar 21, 2022