Vulnerabilities with Nuclei Scanner Templates

Updated 51m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,468 CVEs tracked 53,663 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,324 vendors 43,878 researchers
4,077 results Clear all
CVE-2020-5307 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.81
Phpgurukul Dairy Farm Shop Management System - SQL Injection
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.
CWE-89 Jan 07, 2020
CVE-2020-5192 8.8 HIGH 1 PoC Analysis NUCLEI EPSS 0.42
Phpgurukul Hospital Management System - SQL Injection
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
CWE-89 Jan 06, 2020
CVE-2020-5191 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.03
Phpgurukul Hospital Management System - XSS
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
CWE-79 Jan 06, 2020
CVE-2020-10148 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
Solarwinds Orion Platform - Missing Authentication
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
CWE-306 Dec 29, 2020
CVE-2020-10547 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.92
rConfig <3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CWE-89 Jun 04, 2020
CVE-2020-10546 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.92
rConfig <3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CWE-89 Jun 04, 2020
CVE-2020-10199 8.8 HIGH KEV 10 PoCs Analysis NUCLEI EPSS 0.94
Nexus Repository Manager Java EL Injection RCE
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
CWE-917 Apr 01, 2020
CVE-2020-10257 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.67
Themerex Addons < 1.0.2 - Missing Authorization
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
CWE-862 Mar 10, 2020
CVE-2020-10220 9.8 CRITICAL 4 PoCs Analysis NUCLEI EPSS 0.94
Rconfig 3.x Chained Remote Code Execution
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
CWE-89 Mar 07, 2020
CVE-2020-10189 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
Zohocorp Manageengine Desktop Central - Insecure Deserialization
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
CWE-502 Mar 06, 2020
CVE-2020-0618 8.8 HIGH KEV RANSOMWARE 6 PoCs Analysis NUCLEI EPSS 0.94
Microsoft Sql Server - Insecure Deserialization
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
CWE-502 Feb 11, 2020
CVE-2020-13935 7.5 HIGH 2 PoCs Analysis NUCLEI EPSS 0.92
Apache Tomcat < 7.0.104 - Infinite Loop
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
CWE-835 Jul 14, 2020
CVE-2020-9402 8.8 HIGH NUCLEI EPSS 0.86
Django < 1.11.29 - SQL Injection
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
CWE-89 Mar 05, 2020
CVE-2020-0646 9.8 CRITICAL KEV 2 PoCs Analysis NUCLEI EPSS 0.94
Microsoft .net Framework - Remote Code Execution
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
CWE-91 Jan 14, 2020
CVE-2019-20176 7.5 HIGH 1 Writeup NUCLEI EPSS 0.11
Pureftpd Pure-ftpd - Denial of Service
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CWE-400 Dec 31, 2019
CVE-2019-5544 9.8 CRITICAL KEV RANSOMWARE 2 PoCs Analysis NUCLEI EPSS 0.92
Vmware Horizon Daas < 9.0.0.0 - Out-of-Bounds Write
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CWE-787 Dec 06, 2019
CVE-2019-18217 7.5 HIGH 1 Writeup NUCLEI EPSS 0.03
Proftpd < 1.3.5 - Infinite Loop
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
CWE-835 Oct 21, 2019
CVE-2019-9193 7.2 HIGH EXPLOITED 16 PoCs Analysis NUCLEI EPSS 0.93
Postgresql < 11.2 - OS Command Injection
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
CWE-78 Apr 01, 2019
CVE-2019-6443 9.1 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.44
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
CWE-125 Jan 16, 2019
CVE-2019-25213 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.46
WordPress Advanced Access Manager <5.9.8.1 - Info Disclosure
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
CWE-22 Oct 16, 2024