Vulnerabilities with Nuclei Scanner Templates
Updated 22m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2020-5777
9.8
CRITICAL
NUCLEI
EPSS 0.91
MAGMI <0.7.24 - Auth Bypass
MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.
CWE-287
Sep 01, 2020
CVE-2020-5776
8.8
HIGH
EXPLOITED
NUCLEI
EPSS 0.80
MAGMI - CSRF
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.
CWE-352
Sep 01, 2020
CVE-2020-20627
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.07
Givewp < 2.5.9 - Missing Authentication
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
CWE-306
Aug 31, 2020
CVE-2020-24223
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.15
Mara CMS 7.5 - XSS
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
CWE-79
Aug 30, 2020
CVE-2020-23972
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.73
Joomla Component GMapFP <J3.5/J3.5free - Info Disclosure
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
CWE-434
Aug 27, 2020
CVE-2020-24312
7.5
HIGH
NUCLEI
EPSS 0.52
WP File Manager <6.4 - Info Disclosure
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
CWE-552
Aug 26, 2020
CVE-2020-6637
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.70
Os4ed Opensis - SQL Injection
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
CWE-89
Aug 24, 2020
CVE-2020-24186
10.0
CRITICAL
9 PoCs
Analysis
NUCLEI
EPSS 0.94
gVectors wpDiscuz <7.0.4 - RCE
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
CWE-434
Aug 24, 2020
CVE-2020-24589
9.1
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.90
WSO2 API Manager <3.1.0 - XXE
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
CWE-611
Aug 21, 2020
CVE-2020-5775
5.8
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.71
Canvas LMS 2020-07-29 - SSRF
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
CWE-918
Aug 21, 2020
CVE-2020-24571
7.5
HIGH
NUCLEI
EPSS 0.92
NexusQA NexusDB <4.50.23 - Path Traversal
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
CWE-22
Aug 21, 2020
CVE-2020-17456
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.89
SEOWON INTECH SLC-130,SLR-120S - RCE
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
CWE-78
Aug 20, 2020
CVE-2020-8209
7.5
HIGH
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.93
Citrix XenMobile <10.12 - Info Disclosure
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
CWE-22
Aug 17, 2020
CVE-2020-17463
9.8
CRITICAL
KEV
NUCLEI
EPSS 0.18
FUEL CMS 1.4.7 - SQL Injection
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CWE-89
Aug 13, 2020
CVE-2020-17362
6.1
MEDIUM
NUCLEI
EPSS 0.04
Nova Lite <1.3.9 - XSS
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CWE-79
Aug 12, 2020
CVE-2020-16139
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.88
Cisco Unified IP Conference Station 7937G - DoS
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information
Aug 12, 2020
CVE-2020-17506
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Artica Web Proxy 4.30.00000000 - SQL Injection
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
CWE-89
Aug 12, 2020
CVE-2020-17505
8.8
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.90
Artica proxy 4.30.000000 Auth Bypass service-cmds-peform Command Injection
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
CWE-78
Aug 12, 2020
CVE-2020-17496
9.8
CRITICAL
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.94
vBulletin <5.6.2 - RCE
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
CWE-74
Aug 12, 2020
CVE-2020-16248
5.8
MEDIUM
NUCLEI
EPSS 0.04
Prometheus Blackbox Exporter < 0.17.0 - SSRF
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
CWE-918
Aug 09, 2020