Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-0342 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.92
Zyxel USG/ZyWALL - Auth Bypass
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
CWE-287 Mar 28, 2022
CVE-2022-1040 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 8 PoCs Analysis NUCLEI EPSS 0.94
Sophos Sfos < 18.5.3 - Authentication Bypass
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Mar 25, 2022
CVE-2022-1058 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.05
Gitea < 1.16.5 - Open Redirect
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
CWE-601 Mar 24, 2022
CVE-2022-0760 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.71
Simple Link Directory <7.7.2 - SQL Injection
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
CWE-89 Mar 21, 2022
CVE-2022-0747 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.90
Infographic Maker WP <4.3.8 - SQL Injection
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
CWE-89 Mar 21, 2022
CVE-2022-0591 9.1 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.88
FormCraft WP <3.8.28 - SSRF
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CWE-918 Mar 21, 2022
CVE-2022-0415 8.8 HIGH 1 Writeup NUCLEI EPSS 0.90
gogs <0.12.6 - RCE
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CWE-434 Mar 21, 2022
CVE-2022-0968 5.5 MEDIUM 1 Writeup NUCLEI EPSS 0.01
Microweber < 1.2.12 - Integer Overflow
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.
CWE-190 Mar 15, 2022
CVE-2022-0963 5.4 MEDIUM 1 Writeup NUCLEI EPSS 0.08
Microweber < 1.2.12 - XSS
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CWE-79 Mar 15, 2022
CVE-2022-0954 5.4 MEDIUM 1 Writeup NUCLEI EPSS 0.04
Microweber < 1.2.11 - XSS
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
CWE-79 Mar 15, 2022
CVE-2022-0658 9.8 CRITICAL NUCLEI EPSS 0.47
CommonsBooking <2.6.8 - SQL Injection
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection
CWE-89 Mar 14, 2022
CVE-2022-0169 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.82
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CWE-89 Mar 14, 2022
CVE-2022-0165 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.49
WordPress KingComposer <2.9.6 - Open Redirect
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
CWE-601 Mar 14, 2022
CVE-2022-0147 6.1 MEDIUM NUCLEI EPSS 0.02
WordPress Plugin <2.0.8 - XSS
The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CWE-79 Mar 14, 2022
CVE-2022-0928 5.4 MEDIUM 1 Writeup NUCLEI EPSS 0.05
Microweber < 1.2.11 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CWE-79 Mar 11, 2022
CVE-2022-0870 5.3 MEDIUM 1 Writeup NUCLEI EPSS 0.05
Gogs < 0.12.5 - SSRF
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
CWE-918 Mar 11, 2022
CVE-2022-0482 9.1 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.91
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CWE-359 Mar 09, 2022
CVE-2022-0535 4.8 MEDIUM NUCLEI EPSS 0.02
E2Pdf WordPress <1.16.45 - XSS
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CWE-79 Mar 07, 2022
CVE-2022-0533 6.1 MEDIUM NUCLEI EPSS 0.05
Ditty WordPress Plugin <3.0.15 - XSS
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.
CWE-79 Mar 07, 2022
CVE-2022-0441 9.8 CRITICAL EXPLOITED 6 PoCs Analysis NUCLEI EPSS 0.81
MasterStudy LMS <2.7.6 - Info Disclosure
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CWE-269 Mar 07, 2022