Vulnerabilities with Nuclei Scanner Templates
Updated 6h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2021-42565
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.01
Myfactory Fms < 7.1-912 - XSS
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
CWE-79
Oct 18, 2021
CVE-2021-27561
9.8
CRITICAL
KEV
NUCLEI
EPSS 0.94
Yealink DM 3.6.0.20 - Command Injection
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
CWE-78
Oct 15, 2021
CVE-2021-40542
6.1
MEDIUM
NUCLEI
EPSS 0.25
Opensis-Classic 8.0 - XSS
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
CWE-79
Oct 11, 2021
CVE-2021-29006
6.5
MEDIUM
1 Writeup
NUCLEI
EPSS 0.21
Rconfig - Path Traversal
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
CWE-22
Oct 11, 2021
CVE-2021-42071
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.91
Visual-tools Dvr Vx16 Firmware - OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CWE-78
Oct 07, 2021
CVE-2021-42013
9.8
CRITICAL
KEV
RANSOMWARE
45 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache HTTP Server < 9.2.6.0 - Path Traversal
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CWE-22
Oct 07, 2021
CVE-2021-40978
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.85
Mkdocs 1.2.2 - Path Traversal
The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1
CWE-22
Oct 07, 2021
CVE-2021-32172
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.65
Maianscriptworld Maian Cart - Missing Authorization
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
CWE-862
Oct 07, 2021
CVE-2021-39350
6.1
MEDIUM
NUCLEI
EPSS 0.17
Foliovision FV Flowplayer Video Player < 7.5.2.727 - XSS
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
CWE-79
Oct 06, 2021
CVE-2021-39226
9.8
CRITICAL
KEV
1 Writeup
NUCLEI
EPSS 0.94
Grafana < 7.5.11 - Missing Authorization
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.
CWE-862
Oct 05, 2021
CVE-2021-41773
9.8
CRITICAL
KEV
RANSOMWARE
170 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache 2.4.49/2.4.50 Traversal RCE
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CWE-22
Oct 05, 2021
CVE-2021-39433
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.81
BIQS IT Biqs-drive <1.83 - LFI
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.
Oct 04, 2021
CVE-2021-41878
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.15
Hkurl I-panel Administration System - XSS
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.
CWE-79
Oct 04, 2021
CVE-2021-40323
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
NUCLEI
EPSS 0.93
Cobbler <3.3.0 - RCE
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
CWE-94
Oct 04, 2021
CVE-2021-41467
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.14
Justwriting - XSS
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.
CWE-79
Oct 01, 2021
CVE-2021-40973
6.1
MEDIUM
NUCLEI
EPSS 0.01
spotweb <1.5.1 - XSS
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.
CWE-79
Oct 01, 2021
CVE-2021-40972
6.1
MEDIUM
NUCLEI
EPSS 0.01
spotweb <1.5.1 - XSS
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.
CWE-79
Oct 01, 2021
CVE-2021-40971
6.1
MEDIUM
NUCLEI
EPSS 0.01
Spotweb <1.5.1 - XSS
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.
CWE-79
Oct 01, 2021
CVE-2021-40970
6.1
MEDIUM
NUCLEI
EPSS 0.01
spotweb <1.5.1 - XSS
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.
CWE-79
Oct 01, 2021
CVE-2021-40969
6.1
MEDIUM
NUCLEI
EPSS 0.01
spotweb <1.5.1 - XSS
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.
CWE-79
Oct 01, 2021