Vulnerabilities with Nuclei Scanner Templates
Updated 51m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2020-5307
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.81
Phpgurukul Dairy Farm Shop Management System - SQL Injection
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.
CWE-89
Jan 07, 2020
CVE-2020-5192
8.8
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.42
Phpgurukul Hospital Management System - SQL Injection
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
CWE-89
Jan 06, 2020
CVE-2020-5191
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.03
Phpgurukul Hospital Management System - XSS
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
CWE-79
Jan 06, 2020
CVE-2020-10148
9.8
CRITICAL
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Solarwinds Orion Platform - Missing Authentication
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
CWE-306
Dec 29, 2020
CVE-2020-10547
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.92
rConfig <3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CWE-89
Jun 04, 2020
CVE-2020-10546
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.92
rConfig <3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CWE-89
Jun 04, 2020
CVE-2020-10199
8.8
HIGH
KEV
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Nexus Repository Manager Java EL Injection RCE
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
CWE-917
Apr 01, 2020
CVE-2020-10257
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.67
Themerex Addons < 1.0.2 - Missing Authorization
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
CWE-862
Mar 10, 2020
CVE-2020-10220
9.8
CRITICAL
4 PoCs
Analysis
NUCLEI
EPSS 0.94
Rconfig 3.x Chained Remote Code Execution
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
CWE-89
Mar 07, 2020
CVE-2020-10189
9.8
CRITICAL
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Zohocorp Manageengine Desktop Central - Insecure Deserialization
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
CWE-502
Mar 06, 2020
CVE-2020-0618
8.8
HIGH
KEV
RANSOMWARE
6 PoCs
Analysis
NUCLEI
EPSS 0.94
Microsoft Sql Server - Insecure Deserialization
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
CWE-502
Feb 11, 2020
CVE-2020-13935
7.5
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Apache Tomcat < 7.0.104 - Infinite Loop
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
CWE-835
Jul 14, 2020
CVE-2020-9402
8.8
HIGH
NUCLEI
EPSS 0.86
Django < 1.11.29 - SQL Injection
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
CWE-89
Mar 05, 2020
CVE-2020-0646
9.8
CRITICAL
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Microsoft .net Framework - Remote Code Execution
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
CWE-91
Jan 14, 2020
CVE-2019-20176
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.11
Pureftpd Pure-ftpd - Denial of Service
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CWE-400
Dec 31, 2019
CVE-2019-5544
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Vmware Horizon Daas < 9.0.0.0 - Out-of-Bounds Write
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CWE-787
Dec 06, 2019
CVE-2019-18217
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.03
Proftpd < 1.3.5 - Infinite Loop
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
CWE-835
Oct 21, 2019
CVE-2019-9193
7.2
HIGH
EXPLOITED
16 PoCs
Analysis
NUCLEI
EPSS 0.93
Postgresql < 11.2 - OS Command Injection
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
CWE-78
Apr 01, 2019
CVE-2019-6443
9.1
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.44
Ntpsec < 1.1.3 - Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
CWE-125
Jan 16, 2019
CVE-2019-25213
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.46
WordPress Advanced Access Manager <5.9.8.1 - Info Disclosure
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
CWE-22
Oct 16, 2024