Vulnerabilities with Nuclei Scanner Templates
Updated 9m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,078 results
Clear all
CVE-2022-1609
9.8
CRITICAL
EXPLOITED
SSVC PoC
6 PoCs
Analysis
NUCLEI
EPSS 0.93
Weblizar School Management < 9.9.7 - Code Injection
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
CWE-94
Jan 16, 2024
CVE-2022-21587
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CWE-306
Oct 18, 2022
CVE-2022-22242
6.1
MEDIUM
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.62
Juniper Networks Junos OS <19.1R3-S9-20.2 - XSS
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.
CWE-79
Oct 18, 2022
CVE-2022-1580
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.05
Freehtmldesigns Site Offline < 1.5.3 - IDOR
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.
CWE-639
Sep 19, 2022
CVE-2022-2034
5.3
MEDIUM
NUCLEI
EPSS 0.34
Automattic Sensei Lms < 4.5.0 - IDOR
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
CWE-639
Aug 29, 2022
CVE-2022-22897
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.91
Apollotheme AP Pagebuilder < 2.4.5 - SQL Injection
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
CWE-89
Aug 29, 2022
CVE-2022-2314
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.81
VR Calendar WP <2.3.2 - RCE
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
CWE-78
Aug 15, 2022
CVE-2022-1950
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.60
Youzify WordPress <1.2.0 - SQL Injection
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
CWE-89
Aug 01, 2022
CVE-2022-1906
6.1
MEDIUM
NUCLEI
EPSS 0.06
Copyright Proof WP <4.16 - XSS
The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.
CWE-79
Aug 01, 2022
CVE-2022-2219
7.2
HIGH
NUCLEI
EPSS 0.17
Brizy Unyson < 2.7.27 - XSS
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CWE-79
Jul 25, 2022
CVE-2022-0899
6.1
MEDIUM
NUCLEI
EPSS 0.08
Draftpress Header Footer Code Manager < 1.1.24 - XSS
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.
CWE-79
Jul 25, 2022
CVE-2022-0594
5.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.44
Shareaholic < 9.7.6 - Incorrect Authorization
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
CWE-863
Jul 25, 2022
CVE-2022-2187
6.1
MEDIUM
NUCLEI
EPSS 0.03
Contact Form 7 Captcha <0.1.2 - XSS
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
CWE-79
Jul 17, 2022
CVE-2022-2168
6.1
MEDIUM
NUCLEI
EPSS 0.01
WordPress Plugin <3.2.44 - XSS
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
CWE-79
Jul 17, 2022
CVE-2022-1933
6.1
MEDIUM
NUCLEI
EPSS 0.14
CDI WordPress <5.1.9 - XSS
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
CWE-79
Jul 17, 2022
CVE-2022-1952
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.86
Free Booking Plugin <1.1.16 - RCE
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.
CWE-434
Jul 11, 2022
CVE-2022-1937
6.1
MEDIUM
NUCLEI
EPSS 0.05
Awin Data Feed WP <1.8 - XSS
The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
CWE-79
Jul 11, 2022
CVE-2022-1910
6.1
MEDIUM
NUCLEI
EPSS 0.03
Phlox WordPress <2.9.8 - XSS
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
CWE-79
Jul 11, 2022
CVE-2022-1057
9.8
CRITICAL
NUCLEI
EPSS 0.65
Varktech Pricing Deals For Woocommerce < 2.0.2.02 - SQL Injection
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
CWE-89
Jul 11, 2022
CVE-2022-1946
6.1
MEDIUM
NUCLEI
EPSS 0.01
The Gallery <2.0.0 - XSS
The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue
CWE-79
Jul 04, 2022