Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,534 CVEs tracked 53,639 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,342 vendors 43,887 researchers
4,077 results Clear all
CVE-2021-24970 7.2 HIGH NUCLEI EPSS 0.09
All-in-One Video Gallery <2.5.0 - Code Injection
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue
CWE-22 Dec 13, 2021
CVE-2021-24946 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.60
WordPress Modern Events Calendar SQLi Scanner
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue
CWE-89 Dec 13, 2021
CVE-2021-20137 6.1 MEDIUM NUCLEI EPSS 0.11
Gryphonconnect Gryphon Tower Firmware < 04.0004.12 - XSS
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.
CWE-79 Dec 09, 2021
CVE-2021-20038 9.8 CRITICAL KEV RANSOMWARE 4 PoCs Analysis NUCLEI EPSS 0.94
Sonicwall Sma 200 Firmware - Out-of-Bounds Write
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
CWE-121 Dec 08, 2021
CVE-2021-24943 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.55
Events Calendar <2.7.6 - SQL Injection
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
CWE-89 Dec 06, 2021
CVE-2021-24931 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.72
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
CWE-89 Dec 06, 2021
CVE-2021-24917 7.5 HIGH 3 PoCs Analysis NUCLEI EPSS 0.76
WPS Hide Login <1.9.1 - Info Disclosure
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
CWE-863 Dec 06, 2021
CVE-2021-24915 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.84
Contest Gallery WordPress <13.1.0.6 - SQL Injection
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address
CWE-89 Nov 29, 2021
CVE-2021-24876 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.00
Events Calendar <2.7.5 - XSS
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
CWE-79 Nov 29, 2021
CVE-2021-24891 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.05
Elementor <3.4.8 - XSS
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
CWE-79 Nov 23, 2021
CVE-2021-24875 6.1 MEDIUM NUCLEI EPSS 0.21
WordPress eCommerce Product Catalog <3.0.39 - XSS
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue
CWE-79 Nov 23, 2021
CVE-2021-24644 7.5 HIGH EXPLOITED NUCLEI EPSS 0.30
Imagestowebp Images TO Webp < 1.9 - Path Traversal
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
CWE-22 Nov 23, 2021
CVE-2021-22053 8.8 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
Vmware Spring Cloud Netflix < 2.2.10 - Code Injection
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.
CWE-94 Nov 19, 2021
CVE-2021-24827 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.68
Asgaros Forum WP <1.15.13 - SQL Injection
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
CWE-89 Nov 08, 2021
CVE-2021-24791 7.2 HIGH NUCLEI EPSS 0.06
Header Footer Code Manager <1.1.14 - SQL Injection
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections
CWE-89 Nov 08, 2021
CVE-2021-24731 9.8 CRITICAL NUCLEI EPSS 0.53
WordPress Plugin <3.7.1.6 - SQL Injection
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
CWE-89 Nov 08, 2021
CVE-2021-24647 8.1 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.85
Genetechsolutions Pie Register < 3.7.1.6 - Authentication Bypass
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
CWE-287 Nov 08, 2021
CVE-2021-24627 7.2 HIGH NUCLEI EPSS 0.25
G Auto-hyperlink < 1.0.1 - SQL Injection
The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection
CWE-89 Nov 08, 2021
CVE-2021-20837 9.8 CRITICAL EXPLOITED 7 PoCs Analysis NUCLEI EPSS 0.94
Movable Type <7 r.5002 - RCE
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.
CWE-78 Oct 26, 2021
CVE-2021-21745 4.3 MEDIUM EXPLOITED NUCLEI EPSS 0.36
ZTE Mf971r Firmware - CSRF
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.
CWE-352 Oct 20, 2021