Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
4,077 results Clear all
CVE-2020-36333 9.1 CRITICAL EXPLOITED NUCLEI EPSS 0.46
Themegrill Demo Importer < 1.6.2 - Missing Authentication
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
CWE-306 May 05, 2021
CVE-2020-23015 6.1 MEDIUM NUCLEI EPSS 0.11
OPNsense <20.1.5 - Open Redirect
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
CWE-601 May 03, 2021
CVE-2020-21998 6.1 MEDIUM NUCLEI EPSS 0.01
Homeautomation - Open Redirect
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
CWE-601 Apr 27, 2021
CVE-2020-25864 6.1 MEDIUM NUCLEI EPSS 0.83
Hashicorp Consul < 1.7.14 - XSS
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
CWE-79 Apr 20, 2021
CVE-2020-24285 7.5 HIGH 1 Writeup NUCLEI EPSS 0.13
Intelbras Telephone IP TIP200 <60.61.75.22 - Info Disclosure
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.
Apr 12, 2021
CVE-2020-17453 6.1 MEDIUM EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.67
WSO2 Management Console <5.10 - XSS
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
CWE-79 Apr 05, 2021
CVE-2020-24550 6.1 MEDIUM NUCLEI EPSS 0.66
EpiServer Find <13.2.7 - Open Redirect
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.
CWE-601 Mar 31, 2021
CVE-2020-24391 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.93
mongo-express <1.0.0 - Info Disclosure
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Mar 30, 2021
CVE-2020-19625 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.86
Gridx - Remote Code Execution
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
Mar 26, 2021
CVE-2020-23517 6.1 MEDIUM NUCLEI EPSS 0.06
Aryanic HighMail <2020 - XSS
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
CWE-79 Mar 26, 2021
CVE-2020-27838 6.5 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.85
Redhat Keycloak < 13.0.0 - Authentication Bypass
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
CWE-287 Mar 08, 2021
CVE-2020-24912 6.1 MEDIUM NUCLEI EPSS 0.32
Qcubed < 3.1.1 - XSS
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
CWE-79 Mar 04, 2021
CVE-2020-29047 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.85
Thimpress WP Hotel Booking < 1.10.2 - Insecure Deserialization
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
CWE-502 Mar 03, 2021
CVE-2020-28429 7.3 HIGH NUCLEI EPSS 0.84
Geojson2kml - OS Command Injection
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
CWE-78 Feb 23, 2021
CVE-2020-29453 5.3 MEDIUM NUCLEI EPSS 0.87
Jira Server/Jira Data Center <8.5.11, <8.6.0-8.13.3, <8.14.0-8.15.0...
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
CWE-22 Feb 22, 2021
CVE-2020-21224 9.8 CRITICAL EXPLOITED 1 PoC 1 Writeup NUCLEI EPSS 0.92
Inspur Clusterengine - Remote Code Execution
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
CWE-88 Feb 22, 2021
CVE-2020-27866 8.8 HIGH EXPLOITED NUCLEI EPSS 0.91
Netgear R6330 Firmware < 1.1.0.78 - Authentication Bypass
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11355.
CWE-287 Feb 12, 2021
CVE-2020-28871 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.94
Monitorr - Unrestricted File Upload
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.
CWE-434 Feb 10, 2021
CVE-2020-13117 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.94
Wavlink <2020-05-15 - Command Injection
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
CWE-77 Feb 09, 2021
CVE-2020-22840 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.43
b2evolution CMS <6.11.6 - Open Redirect
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
CWE-601 Feb 09, 2021