Vulnerabilities with Nuclei Scanner Templates
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2019-20210
6.1
MEDIUM
NUCLEI
EPSS 0.00
Cththemes Citybook < 2.3.4 - XSS
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
CWE-79
Jan 13, 2020
CVE-2019-20183
7.2
HIGH
NUCLEI
EPSS 0.55
Employee Records System - Unrestricted File Upload
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.
CWE-434
Jan 09, 2020
CVE-2019-20224
8.8
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.94
Artica Pandora Fms - OS Command Injection
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
CWE-78
Jan 09, 2020
CVE-2019-20141
6.1
MEDIUM
NUCLEI
EPSS 0.12
Laborator Neon - XSS
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
CWE-79
Dec 30, 2019
CVE-2019-17558
7.5
HIGH
KEV
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Solr < 7.7.3 - Injection
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
CWE-74
Dec 30, 2019
CVE-2019-20085
7.5
HIGH
KEV
7 PoCs
Analysis
NUCLEI
EPSS 0.94
TVT Nvms-1000 Firmware - Path Traversal
TVT NVMS-1000 devices allow GET /.. Directory Traversal
CWE-22
Dec 30, 2019
CVE-2019-19781
9.8
CRITICAL
KEV
RANSOMWARE
55 PoCs
Analysis
NUCLEI
EPSS 0.94
Citrix ADC (NetScaler) Directory Traversal Scanner
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CWE-22
Dec 27, 2019
CVE-2019-19985
5.3
MEDIUM
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.80
Icegram Email Subscribers & Newsletters - Missing Authorization
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
CWE-862
Dec 26, 2019
CVE-2019-10758
9.9
CRITICAL
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Mongo-express < 0.54.0 - Code Injection
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
CWE-94
Dec 24, 2019
CVE-2019-19908
6.1
MEDIUM
NUCLEI
EPSS 0.45
Ciprianmp Phpmychat-plus - XSS
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
CWE-79
Dec 20, 2019
CVE-2019-4716
9.8
CRITICAL
KEV
2 PoCs
Analysis
NUCLEI
EPSS 0.93
IBM Planning Analytics <2.0.9 - Privilege Escalation
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CWE-94
Dec 18, 2019
CVE-2019-7481
7.5
HIGH
KEV
RANSOMWARE
NUCLEI
EPSS 0.94
SonicWall SMA100 <9.0.0.3 - Info Disclosure
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
CWE-89
Dec 17, 2019
CVE-2019-19368
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.76
Rumpus FTP Web File Manager 8.2.9.1 - XSS
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts
CWE-79
Dec 16, 2019
CVE-2019-17270
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.94
Yachtcontrol < 2019-10-06 - OS Command Injection
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.
CWE-78
Dec 10, 2019
CVE-2019-14251
7.5
HIGH
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.57
Temenos Channels R15.01 - Path Traversal
An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.
CWE-22
Dec 09, 2019
CVE-2019-7195
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
QNAP Photo Station - Path Traversal
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CWE-22
Dec 05, 2019
CVE-2019-7194
9.8
CRITICAL
KEV
RANSOMWARE
1 PoC
Analysis
NUCLEI
EPSS 0.94
QNAP Photo Station - Path Traversal
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CWE-22
Dec 05, 2019
CVE-2019-7192
9.8
CRITICAL
KEV
RANSOMWARE
3 PoCs
Analysis
NUCLEI
EPSS 0.94
QNAP Photo Station - Info Disclosure
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
CWE-863
Dec 05, 2019
CVE-2019-18922
7.5
HIGH
NUCLEI
EPSS 0.88
Allied Telesis AT-GS950/8 - Path Traversal
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.
CWE-22
Nov 29, 2019
CVE-2019-18957
6.1
MEDIUM
NUCLEI
EPSS 0.05
MicroStrategy <11.1.3 - XSS
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
CWE-79
Nov 14, 2019