Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,077 results Clear all
CVE-2019-20210 6.1 MEDIUM NUCLEI EPSS 0.00
Cththemes Citybook < 2.3.4 - XSS
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
CWE-79 Jan 13, 2020
CVE-2019-20183 7.2 HIGH NUCLEI EPSS 0.55
Employee Records System - Unrestricted File Upload
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.
CWE-434 Jan 09, 2020
CVE-2019-20224 8.8 HIGH 1 PoC Analysis NUCLEI EPSS 0.94
Artica Pandora Fms - OS Command Injection
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
CWE-78 Jan 09, 2020
CVE-2019-20141 6.1 MEDIUM NUCLEI EPSS 0.12
Laborator Neon - XSS
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
CWE-79 Dec 30, 2019
CVE-2019-17558 7.5 HIGH KEV 8 PoCs Analysis NUCLEI EPSS 0.94
Apache Solr < 7.7.3 - Injection
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
CWE-74 Dec 30, 2019
CVE-2019-20085 7.5 HIGH KEV 7 PoCs Analysis NUCLEI EPSS 0.94
TVT Nvms-1000 Firmware - Path Traversal
TVT NVMS-1000 devices allow GET /.. Directory Traversal
CWE-22 Dec 30, 2019
CVE-2019-19781 9.8 CRITICAL KEV RANSOMWARE 55 PoCs Analysis NUCLEI EPSS 0.94
Citrix ADC (NetScaler) Directory Traversal Scanner
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CWE-22 Dec 27, 2019
CVE-2019-19985 5.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.80
Icegram Email Subscribers & Newsletters - Missing Authorization
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
CWE-862 Dec 26, 2019
CVE-2019-10758 9.9 CRITICAL KEV 2 PoCs Analysis NUCLEI EPSS 0.94
Mongo-express < 0.54.0 - Code Injection
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
CWE-94 Dec 24, 2019
CVE-2019-19908 6.1 MEDIUM NUCLEI EPSS 0.45
Ciprianmp Phpmychat-plus - XSS
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
CWE-79 Dec 20, 2019
CVE-2019-4716 9.8 CRITICAL KEV 2 PoCs Analysis NUCLEI EPSS 0.93
IBM Planning Analytics <2.0.9 - Privilege Escalation
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CWE-94 Dec 18, 2019
CVE-2019-7481 7.5 HIGH KEV RANSOMWARE NUCLEI EPSS 0.94
SonicWall SMA100 <9.0.0.3 - Info Disclosure
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
CWE-89 Dec 17, 2019
CVE-2019-19368 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.76
Rumpus FTP Web File Manager 8.2.9.1 - XSS
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts
CWE-79 Dec 16, 2019
CVE-2019-17270 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.94
Yachtcontrol < 2019-10-06 - OS Command Injection
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.
CWE-78 Dec 10, 2019
CVE-2019-14251 7.5 HIGH EXPLOITED 1 Writeup NUCLEI EPSS 0.57
Temenos Channels R15.01 - Path Traversal
An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.
CWE-22 Dec 09, 2019
CVE-2019-7195 9.8 CRITICAL KEV RANSOMWARE 2 PoCs Analysis NUCLEI EPSS 0.94
QNAP Photo Station - Path Traversal
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CWE-22 Dec 05, 2019
CVE-2019-7194 9.8 CRITICAL KEV RANSOMWARE 1 PoC Analysis NUCLEI EPSS 0.94
QNAP Photo Station - Path Traversal
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CWE-22 Dec 05, 2019
CVE-2019-7192 9.8 CRITICAL KEV RANSOMWARE 3 PoCs Analysis NUCLEI EPSS 0.94
QNAP Photo Station - Info Disclosure
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
CWE-863 Dec 05, 2019
CVE-2019-18922 7.5 HIGH NUCLEI EPSS 0.88
Allied Telesis AT-GS950/8 - Path Traversal
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.
CWE-22 Nov 29, 2019
CVE-2019-18957 6.1 MEDIUM NUCLEI EPSS 0.05
MicroStrategy <11.1.3 - XSS
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
CWE-79 Nov 14, 2019