Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,534 CVEs tracked 53,639 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,342 vendors 43,887 researchers
4,077 results Clear all
CVE-2021-20124 7.5 HIGH KEV NUCLEI EPSS 0.94
Draytek Vigorconnect - Path Traversal
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CWE-22 Oct 13, 2021
CVE-2021-20123 7.5 HIGH KEV NUCLEI EPSS 0.94
Draytek Vigorconnect - Path Traversal
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CWE-22 Oct 13, 2021
CVE-2021-20031 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.36
Sonicwall Sonicos < 7.0.1-r1262 - Open Redirect
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
CWE-601 Oct 12, 2021
CVE-2021-24681 4.8 MEDIUM NUCLEI EPSS 0.00
Duplicate Page WP <4.4.2 - XSS
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CWE-79 Oct 11, 2021
CVE-2021-24666 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.82
Podlove Podcast Publisher < 3.5.6 - SQL Injection
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.
CWE-89 Sep 27, 2021
CVE-2021-22017 5.3 MEDIUM KEV NUCLEI EPSS 0.75
vCenter Server - SSRF
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
Sep 23, 2021
CVE-2021-22005 9.8 CRITICAL KEV RANSOMWARE 16 PoCs Analysis NUCLEI EPSS 0.94
Vmware Cloud Foundation < 5.0 - Path Traversal
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
CWE-22 Sep 23, 2021
CVE-2021-24657 6.1 MEDIUM NUCLEI EPSS 0.01
Limit Login Attempts < 4.0.50 - XSS
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.
CWE-79 Sep 20, 2021
CVE-2021-24510 6.1 MEDIUM NUCLEI EPSS 0.21
MF Gig Calendar < 1.1 - XSS
The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue
Sep 13, 2021
CVE-2021-24435 6.1 MEDIUM NUCLEI EPSS 0.13
Gambit Titan Framework < 1.12.1 - XSS
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues
CWE-79 Sep 06, 2021
CVE-2021-24554 7.2 HIGH NUCLEI EPSS 0.21
Freelancetoindia Paytm-pay < 1.3.2 - SQL Injection
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue
CWE-89 Aug 23, 2021
CVE-2021-20792 6.1 MEDIUM NUCLEI EPSS 0.10
Quiz And Survey Master <7.1.14 - XSS
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
CWE-79 Aug 18, 2021
CVE-2021-24527 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.76
Cozmoslabs Profile Builder < 3.4.9 - Authentication Bypass
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.
CWE-287 Aug 16, 2021
CVE-2021-24522 6.1 MEDIUM NUCLEI EPSS 0.00
Properfraction Profilepress < 3.1.11 - XSS
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.
CWE-79 Aug 09, 2021
CVE-2021-24499 9.8 CRITICAL EXPLOITED 6 PoCs Analysis NUCLEI EPSS 0.94
Amentotech Workreap < 2.2.2 - Unrestricted File Upload
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
CWE-434 Aug 09, 2021
CVE-2021-24495 6.1 MEDIUM NUCLEI EPSS 0.32
Marmoset Viewer < 1.9.3 - XSS
The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.
CWE-79 Aug 09, 2021
CVE-2021-21805 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.93
Advantech R-seenet - OS Command Injection
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
CWE-78 Aug 05, 2021
CVE-2021-24498 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.25
Dwbooster Calendar Event Multi View < 1.4.01 - XSS
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
CWE-79 Aug 02, 2021
CVE-2021-24488 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.12
Pickplugins Post Grid < 2.1.8 - XSS
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
CWE-79 Aug 02, 2021
CVE-2021-24472 9.8 CRITICAL NUCLEI EPSS 0.90
Qantumthemes Kentharadio < 2.0.2 - SSRF
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.
CWE-918 Aug 02, 2021