Vulnerabilities with Nuclei Scanner Templates

Updated 9m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,727 CVEs tracked 53,701 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,078 Nuclei templates 52,396 vendors 43,936 researchers
4,078 results Clear all
CVE-2022-25061 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.86
Tp-link Tl-wr840n Firmware - OS Command Injection
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
CWE-78 Feb 25, 2022
CVE-2022-24288 8.8 HIGH EXPLOITED NUCLEI EPSS 0.89
Apache Airflow <2.2.4 - Command Injection
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
CWE-78 Feb 25, 2022
CVE-2022-25149 9.8 CRITICAL NUCLEI EPSS 0.76
Veronalabs WP Statistics < 13.1.5 - SQL Injection
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
CWE-89 Feb 24, 2022
CVE-2022-25148 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.58
Veronalabs WP Statistics < 13.1.5 - SQL Injection
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
CWE-89 Feb 24, 2022
CVE-2022-25082 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.90
Totolink A950rg Firmware - OS Command Injection
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CWE-78 Feb 24, 2022
CVE-2022-25323 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.11
Zerof Web Server - XSS
ZEROF Web Server 2.0 allows /admin.back XSS.
CWE-79 Feb 18, 2022
CVE-2022-25322 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.61
Zerof Web Server - SQL Injection
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
CWE-89 Feb 18, 2022
CVE-2022-24086 9.8 CRITICAL KEV SSVC ACTIVE 10 PoCs Analysis NUCLEI EPSS 0.94
Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CWE-20 Feb 16, 2022
CVE-2022-24112 9.8 CRITICAL KEV SSVC ACTIVE 12 PoCs Analysis NUCLEI EPSS 0.94
APISIX Admin API default access token RCE
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
CWE-290 Feb 11, 2022
CVE-2022-24682 6.1 MEDIUM KEV SSVC ACTIVE RANSOMWARE NUCLEI EPSS 0.88
Zimbra Collaboration Suite <8.8.15 patch 30 (update 1) - XSS
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CWE-116 Feb 09, 2022
CVE-2022-24129 8.2 HIGH 1 Writeup NUCLEI EPSS 0.47
OIDC OP <3.0.4 - SSRF
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.
CWE-918 Feb 04, 2022
CVE-2022-24260 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.91
Voipmonitor GUI <v24.96 - Privilege Escalation
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
CWE-89 Feb 04, 2022
CVE-2022-24223 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.45
AtomCMS v2.0 - SQL Injection
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
CWE-89 Feb 01, 2022
CVE-2022-24266 7.5 HIGH NUCLEI EPSS 0.59
Cuppa CMS v1.0 - SQL Injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
CWE-89 Jan 31, 2022
CVE-2022-24265 7.5 HIGH NUCLEI EPSS 0.55
Cuppa CMS v1.0 - SQL Injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
CWE-89 Jan 31, 2022
CVE-2022-24264 7.5 HIGH NUCLEI EPSS 0.64
Cuppa CMS v1.0 - SQL Injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
CWE-89 Jan 31, 2022
CVE-2022-24124 7.5 HIGH 7 PoCs Analysis NUCLEI EPSS 0.61
Casdoor <1.13.1 - SQL Injection
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
CWE-89 Jan 29, 2022
CVE-2022-23944 9.1 CRITICAL NUCLEI EPSS 0.90
Apache ShenYu <2.4.1 - Info Disclosure
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CWE-862 Jan 25, 2022
CVE-2022-23808 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.49
phpMyAdmin <5.1.2 - Code Injection
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CWE-79 Jan 22, 2022
CVE-2022-23178 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.93
Crestron Hd-md4x2-4k-e Firmware - Authentication Bypass
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
CWE-287 Jan 15, 2022