Vulnerabilities with Nuclei Scanner Templates
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2020-26153
6.1
MEDIUM
NUCLEI
EPSS 0.13
Eventespresso Event Espresso < 4.10.7.p - XSS
A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79
Jul 13, 2021
CVE-2020-35987
5.4
MEDIUM
NUCLEI
EPSS 0.03
Rukovoditel - XSS
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CWE-79
Jul 09, 2021
CVE-2020-35986
5.4
MEDIUM
NUCLEI
EPSS 0.04
Rukovoditel - XSS
A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CWE-79
Jul 09, 2021
CVE-2020-35985
5.4
MEDIUM
NUCLEI
EPSS 0.05
Rukovoditel - XSS
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CWE-79
Jul 09, 2021
CVE-2020-35984
5.4
MEDIUM
NUCLEI
EPSS 0.02
Rukovoditel - XSS
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
CWE-79
Jul 09, 2021
CVE-2020-24148
9.1
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.93
WordPress import-xml-feed <2.0.1 - SSRF
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
CWE-918
Jul 07, 2021
CVE-2020-23697
5.4
MEDIUM
NUCLEI
EPSS 0.26
Monstra CMS 3.0.4 - XSS
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
CWE-79
Jul 06, 2021
CVE-2020-27361
7.5
HIGH
NUCLEI
EPSS 0.89
Akkadian Provisioning Manager <4.50.02 - Info Disclosure
An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.
CWE-668
Jul 01, 2021
CVE-2020-22165
7.5
HIGH
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.37
Phpgurukul Hospital Management System - SQL Injection
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CWE-89
Jun 22, 2021
CVE-2020-22211
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.35
74cms - SQL Injection
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
CWE-89
Jun 16, 2021
CVE-2020-22210
9.8
CRITICAL
NUCLEI
EPSS 0.44
74cms - SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CWE-89
Jun 16, 2021
CVE-2020-22209
9.8
CRITICAL
NUCLEI
EPSS 0.44
74cms - SQL Injection
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CWE-89
Jun 16, 2021
CVE-2020-22208
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.38
74cms - SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CWE-89
Jun 16, 2021
CVE-2020-29214
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.45
SourceCodester Alumni Management System 1.0 - SQL Injection
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
CWE-89
Jun 15, 2021
CVE-2020-18268
6.1
MEDIUM
NUCLEI
EPSS 0.07
Z-BlogPHP <1.5.2 - Open Redirect
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
CWE-601
Jun 07, 2021
CVE-2020-6950
6.5
MEDIUM
1 Writeup
NUCLEI
EPSS 0.52
Eclipse Mojarra < 2.3.14 - Path Traversal
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
CWE-22
Jun 02, 2021
CVE-2020-35580
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.83
Searchblox < 9.2.2 - Path Traversal
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.
CWE-22
May 20, 2021
CVE-2020-36365
6.1
MEDIUM
NUCLEI
EPSS 0.10
Smartstorenet < 4.1.0 - Open Redirect
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
CWE-601
May 19, 2021
CVE-2020-36289
5.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.92
Atlassian Data Center < 8.5.13 - Incorrect Authorization
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
CWE-863
May 12, 2021
CVE-2020-23575
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.87
Kyocera Printer d-COPIA253MF - Path Traversal
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.
CWE-22
May 10, 2021