Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-27043
7.5
HIGH
NUCLEI
EPSS 0.26
Yearning < 2.3.6 - Path Traversal
Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.
CWE-22
Apr 15, 2022
CVE-2022-24816
10.0
CRITICAL
KEV
SSVC ACTIVE
1 PoC
Analysis
NUCLEI
EPSS 0.94
Geosolutionsgroup Jai-ext < 1.1.22 - Code Injection
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.
CWE-94
Apr 13, 2022
CVE-2022-28033
9.8
CRITICAL
NUCLEI
EPSS 0.58
Thedigitalcraft Atomcms - SQL Injection
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
CWE-89
Apr 12, 2022
CVE-2022-28032
9.8
CRITICAL
NUCLEI
EPSS 0.47
Thedigitalcraft Atomcms - SQL Injection
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
CWE-89
Apr 12, 2022
CVE-2022-28365
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.56
Reprise License Manager 14.2 - Info Disclosure
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
CWE-425
Apr 09, 2022
CVE-2022-28363
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.05
Reprise License Manager 14.2 - XSS
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
CWE-79
Apr 09, 2022
CVE-2022-24819
5.3
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.04
XWiki Platform - Info Disclosure
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.
CWE-359
Apr 08, 2022
CVE-2022-24681
6.1
MEDIUM
NUCLEI
EPSS 0.23
Zoho ManageEngine ADSelfService Plus <6.12.1 - XSS
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
CWE-79
Apr 07, 2022
CVE-2022-28219
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.94
ManageEngine ADAudit Plus CVE-2022-28219
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CWE-611
Apr 05, 2022
CVE-2022-25356
5.3
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.73
Alt-N MDaemon Security Gateway <8.5.0 - XML Injection
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
CWE-91
Apr 05, 2022
CVE-2022-26585
9.8
CRITICAL
1 PoC
NUCLEI
EPSS 0.48
Mingsoft MCMS <5.2.7 - SQL Injection
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CWE-89
Apr 05, 2022
CVE-2022-26233
7.5
HIGH
NUCLEI
EPSS 0.70
Barco Control Room Management <2.9 Build 0275 - Path Traversal
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
CWE-22
Apr 03, 2022
CVE-2022-24181
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.04
PKP Open Journals System >=2.4.8 - XSS
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
CWE-79
Apr 01, 2022
CVE-2022-26271
7.5
HIGH
NUCLEI
EPSS 0.13
74cmsSE v3.4.1 - Info Disclosure
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
CWE-552
Mar 28, 2022
CVE-2022-26263
6.1
MEDIUM
NUCLEI
EPSS 0.10
Yonyou u8 <13.0 - XSS
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
CWE-79
Mar 25, 2022
CVE-2022-25568
7.5
HIGH
NUCLEI
EPSS 0.85
MotionEye Config Info Disclosure
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
CWE-1188
Mar 24, 2022
CVE-2022-23881
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.87
ZZZCMS zzzphp <2.1.0 - RCE
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
Mar 23, 2022
CVE-2022-27228
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.92
Bitrix24 < 21.0.100 - Improper Input Validation
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
CWE-20
Mar 22, 2022
CVE-2022-26148
9.8
CRITICAL
NUCLEI
EPSS 0.90
Grafana & Zabbix Integration - Credentials Disclosure
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.
CWE-312
Mar 21, 2022
CVE-2022-23348
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.01
BigAnt Server <5.6.06 - Info Disclosure
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CWE-916
Mar 21, 2022