Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
4,077 results Clear all
CVE-2020-28653 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.93
Zohocorp Manageengine Opmanager < 12.5 - Remote Code Execution
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
Feb 03, 2021
CVE-2020-29164 6.1 MEDIUM NUCLEI EPSS 0.10
Rainbowfishsoftware Pacsone Server < 7.1.1 - XSS
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
CWE-79 Feb 03, 2021
CVE-2020-25506 9.8 CRITICAL KEV NUCLEI EPSS 0.94
Dlink Dns-320 Firmware - OS Command Injection
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
CWE-78 Feb 02, 2021
CVE-2020-15568 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
TerraMaster TOS <4.1.29 - Code Injection
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
CWE-913 Jan 30, 2021
CVE-2020-27735 6.1 MEDIUM NUCLEI EPSS 0.56
Wftpserver Wing FTP Server - XSS
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
CWE-79 Jan 26, 2021
CVE-2020-19363 6.5 MEDIUM EXPLOITED 1 Writeup NUCLEI EPSS 0.06
Vtiger Crm - Information Disclosure
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
CWE-200 Jan 20, 2021
CVE-2020-19360 7.5 HIGH 2 PoCs Analysis NUCLEI EPSS 0.87
Fhem - Path Traversal
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
CWE-22 Jan 20, 2021
CVE-2020-35749 7.7 HIGH 3 PoCs Analysis NUCLEI EPSS 0.77
Presstigers Simple Board Job < 2.9.3 - Path Traversal
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.
CWE-22 Jan 15, 2021
CVE-2020-24701 6.1 MEDIUM NUCLEI EPSS 0.25
Open-xchange Appsuite < 7.10.4 - XSS
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
CWE-79 Jan 12, 2021
CVE-2020-28208 5.3 MEDIUM NUCLEI EPSS 0.36
Rocket.chat < 3.9.1 - Information Disclosure
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
CWE-203 Jan 08, 2021
CVE-2020-35131 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Cockpit <0.6.1 - RCE
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
CWE-94 Jan 08, 2021
CVE-2020-24903 6.1 MEDIUM NUCLEI EPSS 0.07
Cutesoft Cute Editor - XSS
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CWE-79 Jan 07, 2021
CVE-2020-24902 4.7 MEDIUM NUCLEI EPSS 0.07
Quixplorer < 2.4.1 - XSS
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CWE-79 Jan 07, 2021
CVE-2020-17519 7.5 HIGH KEV 16 PoCs Analysis NUCLEI EPSS 0.94
Apache Flink JobManager Traversal
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
CWE-552 Jan 05, 2021
CVE-2020-17518 7.5 HIGH EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.94
Apache Flink <1.11.3-1.12.0 - Path Traversal
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.
CWE-22 Jan 05, 2021
CVE-2020-36155 10.0 CRITICAL EXPLOITED NUCLEI EPSS 0.62
Ultimatemember Ultimate Member - Improper Privilege Management
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
CWE-269 Jan 04, 2021
CVE-2020-36112 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.89
Cse Bookstore - SQL Injection
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.
CWE-89 Jan 04, 2021
CVE-2020-35951 9.9 CRITICAL NUCLEI EPSS 0.58
Expresstech Quiz And Survey Master < 7.0.1 - Missing Authentication
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
CWE-306 Jan 01, 2021
CVE-2020-35848 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.93
Agentejo Cockpit < 0.11.2 - SQL Injection
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
CWE-89 Dec 30, 2020
CVE-2020-35847 9.8 CRITICAL 3 PoCs Analysis NUCLEI EPSS 0.94
Cockpit CMS NoSQLi to RCE
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
CWE-89 Dec 30, 2020