Vulnerabilities with Nuclei Scanner Templates
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2020-36333
9.1
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.46
Themegrill Demo Importer < 1.6.2 - Missing Authentication
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
CWE-306
May 05, 2021
CVE-2020-23015
6.1
MEDIUM
NUCLEI
EPSS 0.11
OPNsense <20.1.5 - Open Redirect
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
CWE-601
May 03, 2021
CVE-2020-21998
6.1
MEDIUM
NUCLEI
EPSS 0.01
Homeautomation - Open Redirect
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
CWE-601
Apr 27, 2021
CVE-2020-25864
6.1
MEDIUM
NUCLEI
EPSS 0.83
Hashicorp Consul < 1.7.14 - XSS
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
CWE-79
Apr 20, 2021
CVE-2020-24285
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.13
Intelbras Telephone IP TIP200 <60.61.75.22 - Info Disclosure
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.
Apr 12, 2021
CVE-2020-17453
6.1
MEDIUM
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.67
WSO2 Management Console <5.10 - XSS
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
CWE-79
Apr 05, 2021
CVE-2020-24550
6.1
MEDIUM
NUCLEI
EPSS 0.66
EpiServer Find <13.2.7 - Open Redirect
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.
CWE-601
Mar 31, 2021
CVE-2020-24391
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.93
mongo-express <1.0.0 - Info Disclosure
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Mar 30, 2021
CVE-2020-19625
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.86
Gridx - Remote Code Execution
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
Mar 26, 2021
CVE-2020-23517
6.1
MEDIUM
NUCLEI
EPSS 0.06
Aryanic HighMail <2020 - XSS
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
CWE-79
Mar 26, 2021
CVE-2020-27838
6.5
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.85
Redhat Keycloak < 13.0.0 - Authentication Bypass
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
CWE-287
Mar 08, 2021
CVE-2020-24912
6.1
MEDIUM
NUCLEI
EPSS 0.32
Qcubed < 3.1.1 - XSS
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
CWE-79
Mar 04, 2021
CVE-2020-29047
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.85
Thimpress WP Hotel Booking < 1.10.2 - Insecure Deserialization
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
CWE-502
Mar 03, 2021
CVE-2020-28429
7.3
HIGH
NUCLEI
EPSS 0.84
Geojson2kml - OS Command Injection
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
CWE-78
Feb 23, 2021
CVE-2020-29453
5.3
MEDIUM
NUCLEI
EPSS 0.87
Jira Server/Jira Data Center <8.5.11, <8.6.0-8.13.3, <8.14.0-8.15.0...
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
CWE-22
Feb 22, 2021
CVE-2020-21224
9.8
CRITICAL
EXPLOITED
1 PoC
1 Writeup
NUCLEI
EPSS 0.92
Inspur Clusterengine - Remote Code Execution
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
CWE-88
Feb 22, 2021
CVE-2020-27866
8.8
HIGH
EXPLOITED
NUCLEI
EPSS 0.91
Netgear R6330 Firmware < 1.1.0.78 - Authentication Bypass
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11355.
CWE-287
Feb 12, 2021
CVE-2020-28871
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Monitorr - Unrestricted File Upload
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.
CWE-434
Feb 10, 2021
CVE-2020-13117
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.94
Wavlink <2020-05-15 - Command Injection
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
CWE-77
Feb 09, 2021
CVE-2020-22840
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.43
b2evolution CMS <6.11.6 - Open Redirect
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
CWE-601
Feb 09, 2021