Vulnerabilities with Nuclei Scanner Templates
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-0660
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.08
Packagist microweber/microweber <1.2.11 - Info Disclosure
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CWE-209
Feb 18, 2022
CVE-2022-0597
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.01
Packagist microweber/microweber <1.2.11 - Open Redirect
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CWE-601
Feb 15, 2022
CVE-2022-0212
6.1
MEDIUM
NUCLEI
EPSS 0.02
SpiderCalendar <1.5.65 - XSS
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
CWE-79
Feb 14, 2022
CVE-2022-0208
6.1
MEDIUM
NUCLEI
EPSS 0.04
MapPress Maps <2.73.4 - XSS
The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
CWE-79
Feb 14, 2022
CVE-2022-0206
6.1
MEDIUM
NUCLEI
EPSS 0.01
NewStatPress <1.3.6 - XSS
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CWE-79
Feb 14, 2022
CVE-2022-0201
6.1
MEDIUM
NUCLEI
EPSS 0.18
Permalink Manager Lite/Pro <2.2.15 - XSS
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
CWE-79
Feb 14, 2022
CVE-2022-0188
5.3
MEDIUM
NUCLEI
EPSS 0.06
CMP WordPress <4.0.19 - Info Disclosure
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
CWE-306
Feb 14, 2022
CVE-2022-22536
10.0
CRITICAL
KEV
SSVC ACTIVE
8 PoCs
Analysis
NUCLEI
EPSS 0.94
SAP NetWeaver - Request Smuggling
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
CWE-444
Feb 09, 2022
CVE-2022-23102
6.1
MEDIUM
NUCLEI
EPSS 0.05
Siemens Sinema Remote Connect Server < 2.0 - Open Redirect
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
CWE-601
Feb 09, 2022
CVE-2022-0149
6.1
MEDIUM
NUCLEI
EPSS 0.01
WooCommerce Stored Exporter <2.7.1 - XSS
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.
CWE-79
Feb 07, 2022
CVE-2022-0148
5.4
MEDIUM
NUCLEI
EPSS 0.09
WordPress Plugin <2.0.4 - XSS
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
CWE-79
Feb 07, 2022
CVE-2022-0437
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.25
NPM karma <6.3.14 - XSS
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
CWE-79
Feb 05, 2022
CVE-2022-0381
6.1
MEDIUM
NUCLEI
EPSS 0.04
Embed Swagger WordPress <1.0.0 - XSS
The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.
CWE-79
Feb 04, 2022
CVE-2022-0218
8.3
HIGH
EXPLOITED
NUCLEI
EPSS 0.62
WP HTML Mail <3.0.9 - Info Disclosure
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.
CWE-862
Feb 04, 2022
CVE-2022-0432
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.57
Mastodon <3.5.0 - Info Disclosure
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
CWE-1321
Feb 02, 2022
CVE-2022-0220
6.1
MEDIUM
NUCLEI
EPSS 0.03
WordPress GDPR <1.9.27 - XSS
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)
CWE-116
Feb 01, 2022
CVE-2022-0378
5.4
MEDIUM
1 Writeup
NUCLEI
EPSS 0.07
Packagist microweber/microweber <1.2.11 - XSS
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CWE-79
Jan 26, 2022
CVE-2022-22733
6.5
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.78
Apache Shardingsphere Elasticjob-ui - Information Disclosure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.
CWE-200
Jan 20, 2022
CVE-2022-0281
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.19
Packagist microweber/microweber <1.2.11 - Info Disclosure
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CWE-200
Jan 20, 2022
CVE-2022-21371
7.5
HIGH
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.93
Oracle Weblogic Server - Path Traversal
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CWE-22
Jan 19, 2022