Vulnerabilities with Nuclei Scanner Templates
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2021-27309
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.01
Clansphere CMS 2011.4 - XSS
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
CWE-79
Mar 23, 2021
CVE-2021-26295
9.8
CRITICAL
EXPLOITED
7 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache OFBiz SOAP Java Deserialization
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
CWE-502
Mar 22, 2021
CVE-2021-27520
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.02
FUDForum 3.1.0 - XSS
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.
CWE-79
Mar 19, 2021
CVE-2021-27519
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.04
FUDForum 3.1.0 - XSS
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.
CWE-79
Mar 19, 2021
CVE-2021-27358
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.87
Grafana 6.7.3-7.4.1 - DoS
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Mar 18, 2021
CVE-2021-26294
7.5
HIGH
EXPLOITED
1 PoC
1 Writeup
NUCLEI
EPSS 0.92
Afterlogic Aurora < 7.7.9 - Path Traversal
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).
CWE-22
Mar 07, 2021
CVE-2021-3377
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.37
Ansi UP < 5.0.0 - XSS
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
CWE-79
Mar 05, 2021
CVE-2021-27964
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.82
SonLogger - Arbitrary File Upload
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.
CWE-434
Mar 05, 2021
CVE-2021-27314
9.8
CRITICAL
NUCLEI
EPSS 0.79
Doctor Appointment System 1.0 - SQL Injection
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
CWE-89
Mar 05, 2021
CVE-2021-27931
9.1
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.89
LumisXP <10.0.0 - Blind XML External Entity Attack
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.
CWE-611
Mar 03, 2021
CVE-2021-26855
9.1
CRITICAL
KEV
RANSOMWARE
67 PoCs
Analysis
NUCLEI
EPSS 0.94
Microsoft Exchange ProxyLogon RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
CWE-918
Mar 03, 2021
CVE-2021-26702
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.03
Eprints - XSS
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
CWE-79
Mar 01, 2021
CVE-2021-26475
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.50
Eprints - XSS
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
CWE-79
Mar 01, 2021
CVE-2021-27132
9.8
CRITICAL
NUCLEI
EPSS 0.76
Sercomm Agcombo Vd625 Firmware - Injection
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
CWE-74
Feb 27, 2021
CVE-2021-27330
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.22
Triconsole Datepicker Calendar <3.77 - XSS
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.
CWE-79
Feb 25, 2021
CVE-2021-27670
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.93
Appspace 6.2.4 - SSRF
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
CWE-918
Feb 25, 2021
CVE-2021-27124
6.5
MEDIUM
NUCLEI
EPSS 0.22
Doctor Appointment System - SQL Injection
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
CWE-89
Feb 18, 2021
CVE-2021-3293
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.62
emlog v5.3.1 - Info Disclosure
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
Feb 08, 2021
CVE-2021-26723
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.64
Jenzabar < 9.2.2 - XSS
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
CWE-79
Feb 06, 2021
CVE-2021-26710
6.1
MEDIUM
NUCLEI
EPSS 0.21
Redwood Report2web - XSS
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.
CWE-79
Feb 05, 2021