Vulnerabilities with Nuclei Scanner Templates
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-0342
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.92
Zyxel USG/ZyWALL - Auth Bypass
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
CWE-287
Mar 28, 2022
CVE-2022-1040
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Sophos Sfos < 18.5.3 - Authentication Bypass
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Mar 25, 2022
CVE-2022-1058
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.05
Gitea < 1.16.5 - Open Redirect
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
CWE-601
Mar 24, 2022
CVE-2022-0760
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.71
Simple Link Directory <7.7.2 - SQL Injection
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
CWE-89
Mar 21, 2022
CVE-2022-0747
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.90
Infographic Maker WP <4.3.8 - SQL Injection
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
CWE-89
Mar 21, 2022
CVE-2022-0591
9.1
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.88
FormCraft WP <3.8.28 - SSRF
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CWE-918
Mar 21, 2022
CVE-2022-0415
8.8
HIGH
1 Writeup
NUCLEI
EPSS 0.90
gogs <0.12.6 - RCE
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CWE-434
Mar 21, 2022
CVE-2022-0968
5.5
MEDIUM
1 Writeup
NUCLEI
EPSS 0.01
Microweber < 1.2.12 - Integer Overflow
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.
CWE-190
Mar 15, 2022
CVE-2022-0963
5.4
MEDIUM
1 Writeup
NUCLEI
EPSS 0.08
Microweber < 1.2.12 - XSS
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CWE-79
Mar 15, 2022
CVE-2022-0954
5.4
MEDIUM
1 Writeup
NUCLEI
EPSS 0.04
Microweber < 1.2.11 - XSS
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
CWE-79
Mar 15, 2022
CVE-2022-0658
9.8
CRITICAL
NUCLEI
EPSS 0.47
CommonsBooking <2.6.8 - SQL Injection
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection
CWE-89
Mar 14, 2022
CVE-2022-0169
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.82
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CWE-89
Mar 14, 2022
CVE-2022-0165
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.49
WordPress KingComposer <2.9.6 - Open Redirect
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
CWE-601
Mar 14, 2022
CVE-2022-0147
6.1
MEDIUM
NUCLEI
EPSS 0.02
WordPress Plugin <2.0.8 - XSS
The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CWE-79
Mar 14, 2022
CVE-2022-0928
5.4
MEDIUM
1 Writeup
NUCLEI
EPSS 0.05
Microweber < 1.2.11 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CWE-79
Mar 11, 2022
CVE-2022-0870
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.05
Gogs < 0.12.5 - SSRF
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
CWE-918
Mar 11, 2022
CVE-2022-0482
9.1
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.91
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CWE-359
Mar 09, 2022
CVE-2022-0535
4.8
MEDIUM
NUCLEI
EPSS 0.02
E2Pdf WordPress <1.16.45 - XSS
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CWE-79
Mar 07, 2022
CVE-2022-0533
6.1
MEDIUM
NUCLEI
EPSS 0.05
Ditty WordPress Plugin <3.0.15 - XSS
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.
CWE-79
Mar 07, 2022
CVE-2022-0441
9.8
CRITICAL
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.81
MasterStudy LMS <2.7.6 - Info Disclosure
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CWE-269
Mar 07, 2022