Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,432 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,077 results Clear all
CVE-2019-17506 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.94
Dlink Dir-868l B1 Firmware - Missing Authentication
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.
CWE-306 Oct 11, 2019
CVE-2019-17503 5.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.90
Kirona DRS 5.5.3.5 - Info Disclosure
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.
CWE-425 Oct 11, 2019
CVE-2019-17418 7.2 HIGH NUCLEI EPSS 0.94
Metinfo - SQL Injection
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
CWE-89 Oct 10, 2019
CVE-2019-15859 9.8 CRITICAL NUCLEI EPSS 0.82
Socomec DIRIS A-40 <48250501 - Info Disclosure
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
CWE-200 Oct 09, 2019
CVE-2019-17382 9.1 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.94
Zabbix < 4.4 - IDOR
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
CWE-639 Oct 09, 2019
CVE-2019-17233 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.01
Etoilewebdesign Ultimate Faq < 1.8.24 - XSS
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
CWE-79 Oct 07, 2019
CVE-2019-17232 7.5 HIGH EXPLOITED NUCLEI EPSS 0.09
Etoilewebdesign Ultimate Faq < 1.8.24 - Missing Authentication
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
CWE-306 Oct 07, 2019
CVE-2019-16931 6.1 MEDIUM NUCLEI EPSS 0.02
Themeisle Visualizer < 3.3.0 - XSS
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
CWE-79 Oct 03, 2019
CVE-2019-16932 10.0 CRITICAL EXPLOITED NUCLEI EPSS 0.81
Themeisle Visualizer < 3.3.1 - SSRF
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
CWE-918 Sep 30, 2019
CVE-2019-16997 7.2 HIGH NUCLEI EPSS 0.94
Metinfo - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
CWE-89 Sep 30, 2019
CVE-2019-16996 7.2 HIGH EXPLOITED NUCLEI EPSS 0.92
Metinfo - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
CWE-89 Sep 30, 2019
CVE-2019-16920 9.8 CRITICAL KEV RANSOMWARE 2 PoCs Analysis NUCLEI EPSS 0.94
Dlink Dir-655 Firmware < 3.02b05 - OS Command Injection
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
CWE-78 Sep 27, 2019
CVE-2019-10092 6.1 MEDIUM 3 PoCs Analysis NUCLEI EPSS 0.82
Apache HTTP Server <2.4.40 - XSS
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
CWE-79 Sep 26, 2019
CVE-2019-10098 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.80
Apache HTTP Server <2.4.40 - SSRF
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
CWE-601 Sep 25, 2019
CVE-2019-10405 5.4 MEDIUM NUCLEI EPSS 0.80
Jenkins < 2.176.3 - XSS
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.
CWE-79 Sep 25, 2019
CVE-2019-16759 9.8 CRITICAL KEV 17 PoCs Analysis NUCLEI EPSS 0.94
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CWE-94 Sep 24, 2019
CVE-2019-16525 6.1 MEDIUM NUCLEI EPSS 0.14
WordPress <1.1.9 - XSS
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
CWE-79 Sep 19, 2019
CVE-2019-16057 9.8 CRITICAL KEV RANSOMWARE NUCLEI EPSS 0.94
D-Link DNS-320 - Command Injection
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CWE-78 Sep 16, 2019
CVE-2019-16332 6.1 MEDIUM NUCLEI EPSS 0.22
WordPress <20190907 - XSS
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CWE-79 Sep 15, 2019
CVE-2019-16313 7.5 HIGH NUCLEI EPSS 0.94
ifw8 Router ROM <4.31 - Info Disclosure
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
CWE-798 Sep 14, 2019