Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2021-45027
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.17
Softlinkint Oliver V5 Library - Download Without Integrity Check
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
CWE-494
Sep 01, 2022
CVE-2021-42627
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.74
D-Link DIR-615 <20.06 - Info Disclosure
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
Aug 23, 2022
CVE-2021-41419
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.77
Qvis Dvr Firmware < 2021-12-13 - Insecure Deserialization
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
CWE-502
Jul 18, 2022
CVE-2021-40150
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.34
E1 Zoom camera <3.0.0.716 - Info Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.
CWE-552
Jul 17, 2022
CVE-2021-40149
5.9
MEDIUM
1 Writeup
NUCLEI
EPSS 0.63
E1 Zoom Camera <3.0.0.716 - Info Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
CWE-552
Jul 17, 2022
CVE-2021-41460
7.5
HIGH
NUCLEI
EPSS 0.45
Shopex Ecshop - SQL Injection
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
CWE-89
Jun 28, 2022
CVE-2021-41432
5.4
MEDIUM
NUCLEI
EPSS 0.12
Flatpress - XSS
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
CWE-79
Jun 23, 2022
CVE-2021-41749
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.86
Nystudio107 Seomatic < 3.4.11 - Code Injection
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
CWE-94
Jun 12, 2022
CVE-2021-37589
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.78
Virtuasoftware Cobranca < 12r - SQL Injection
Virtua Cobranca before 12R allows SQL Injection on the login page.
CWE-89
Jun 07, 2022
CVE-2021-42887
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.61
TOTOLINK EX1200T V4.1.2cu.5215 - Auth Bypass
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Jun 03, 2022
CVE-2021-42192
8.8
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.23
Konga - Incorrect Authorization
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
CWE-863
May 04, 2022
CVE-2021-40822
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.93
GeoServer <2.19.2 - SSRF
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
CWE-918
May 02, 2022
CVE-2021-46424
9.1
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.91
Telesquare TLR-2005KSH 1.0.0 - File Deletion
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.
Apr 27, 2022
CVE-2021-46422
9.8
CRITICAL
EXPLOITED
16 PoCs
Analysis
NUCLEI
EPSS 0.94
Telesquare SDT-CW3B1 1.1.0 - Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
CWE-78
Apr 27, 2022
CVE-2021-35250
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.90
Serv-U <15.3 - Path Traversal
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
CWE-22
Apr 25, 2022
CVE-2021-43287
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.87
ThoughtWorks GoCD <21.3.0 - Info Disclosure
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.
CWE-200
Apr 14, 2022
CVE-2021-31805
9.8
CRITICAL
EXPLOITED
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Struts < 2.5.29 - Remote Code Execution
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
CWE-917
Apr 12, 2022
CVE-2021-37292
7.2
HIGH
NUCLEI
EPSS 0.13
KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 - Pri...
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.
Apr 11, 2022
CVE-2021-37291
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.57
Kevinlab 4st L-bems - SQL Injection
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
CWE-89
Apr 11, 2022
CVE-2021-43421
9.8
CRITICAL
NUCLEI
EPSS 0.80
Studio-42 elFinder <2.1.59 - RCE
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
CWE-434
Apr 07, 2022