Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-0140 5.3 MEDIUM NUCLEI EPSS 0.12
Visual Form Builder <3.0.6 - Info Disclosure
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
CWE-306 Apr 12, 2022
CVE-2022-22954 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 28 PoCs Analysis NUCLEI EPSS 0.94
VMware Workspace ONE Access CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
CWE-94 Apr 11, 2022
CVE-2022-1007 6.1 MEDIUM NUCLEI EPSS 0.04
Elbtide Advanced Booking Calendar < 1.7.1 - XSS
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
CWE-79 Apr 11, 2022
CVE-2022-0949 9.8 CRITICAL NUCLEI EPSS 0.62
Stopbadbots Block And Stop Bad Bots < 6.930 - SQL Injection
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection
CWE-89 Apr 11, 2022
CVE-2022-0271 6.1 MEDIUM NUCLEI EPSS 0.04
LearnPress <4.1.6 - XSS
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting
CWE-79 Apr 11, 2022
CVE-2022-1162 9.1 CRITICAL 4 PoCs Analysis NUCLEI EPSS 0.88
Gitlab < 14.7.7 - Hard-coded Credentials
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts
CWE-798 Apr 04, 2022
CVE-2022-1170 6.1 MEDIUM NUCLEI EPSS 0.01
Nootheme Jobmonster < 4.5.2.9 - XSS
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
CWE-79 Apr 04, 2022
CVE-2022-1168 6.1 MEDIUM NUCLEI EPSS 0.02
Eyecix Jobsearch WP Job Board < 1.5.1 - XSS
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
CWE-79 Apr 04, 2022
CVE-2022-0864 6.1 MEDIUM NUCLEI EPSS 0.03
Updraftplus < 1.22.9 - XSS
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
CWE-79 Apr 04, 2022
CVE-2022-1026 8.6 HIGH EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.87
Kyocera Net Viewer - Insufficiently Protected Credentials
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.
CWE-522 Apr 04, 2022
CVE-2022-22965 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 119 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Framework < 5.2.20 - Code Injection
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CWE-94 Apr 01, 2022
CVE-2022-22963 9.8 CRITICAL KEV SSVC ACTIVE 35 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Cloud Function < 3.1.6 - Remote Code Execution
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CWE-917 Apr 01, 2022
CVE-2022-0735 10.0 CRITICAL NUCLEI EPSS 0.57
GitLab CE/EE <14.6.5-14.8.2 - Info Disclosure
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.
Mar 28, 2022
CVE-2022-0846 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.71
Speakout! Email Petitions < 2.14.15.1 - SQL Injection
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users
CWE-89 Mar 28, 2022
CVE-2022-0787 9.8 CRITICAL NUCLEI EPSS 0.47
WordPress Plugin <5.1 - SQL Injection
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
CWE-89 Mar 28, 2022
CVE-2022-0784 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.75
Title Experiments Free WP <9.0.1 - SQL Injection
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection
CWE-89 Mar 28, 2022
CVE-2022-0679 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.84
Narnoo Distributor WordPress <2.5.1 - Info Disclosure
The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.
CWE-22 Mar 28, 2022
CVE-2022-0599 6.1 MEDIUM NUCLEI EPSS 0.02
WordPress Plugin <5.8 - XSS
The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CWE-79 Mar 28, 2022
CVE-2022-0595 5.4 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.06
WordPress <1.3.6.3 - XSS
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
CWE-79 Mar 28, 2022
CVE-2022-0479 9.8 CRITICAL NUCLEI EPSS 0.76
Popup Builder WordPress <4.1.1 - SQL Injection
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link
CWE-89 Mar 28, 2022