Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2019-8451
6.5
MEDIUM
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.93
Atlassian Jira Server < 8.4.0 - SSRF
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
CWE-918
Sep 11, 2019
CVE-2019-8449
5.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.71
Atlassian Jira < 8.4.0 - Missing Authentication
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
CWE-306
Sep 11, 2019
CVE-2019-6793
7.0
HIGH
NUCLEI
EPSS 0.05
Gitlab < 11.5.8 - SSRF
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.
CWE-918
Sep 09, 2019
CVE-2019-16123
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.48
Kartatopia PilusCart <1.4.1 - Info Disclosure
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
CWE-22
Sep 09, 2019
CVE-2019-16097
6.5
MEDIUM
6 PoCs
Analysis
NUCLEI
EPSS 0.94
Harbor 1.7.0-1.8.2 - Privilege Escalation
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.
CWE-862
Sep 08, 2019
CVE-2019-14223
6.1
MEDIUM
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.37
Alfresco Community Edition <5.2.6, 6.0.N, 6.1.N - Open Redirect
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).
CWE-601
Sep 06, 2019
CVE-2019-14470
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.28
cosenary Instagram-PHP-API <4.9.32 - XSS
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
CWE-79
Sep 04, 2019
CVE-2019-15889
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.06
WordPress <2.9.94 - XSS
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
CWE-79
Sep 03, 2019
CVE-2019-15043
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.91
Grafana < 5.4.5 - Missing Authentication
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CWE-306
Sep 03, 2019
CVE-2019-15858
8.8
HIGH
8 PoCs
Analysis
NUCLEI
EPSS 0.70
Woody ad snippets <2.2.5 - RCE
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
CWE-306
Sep 03, 2019
CVE-2019-15829
4.8
MEDIUM
NUCLEI
EPSS 0.02
WordPress <1.1.33 - XSS
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
CWE-79
Aug 30, 2019
CVE-2019-15823
9.8
CRITICAL
NUCLEI
EPSS 0.51
wps-hide-login <1.5.3 - Auth Bypass
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
Aug 30, 2019
CVE-2019-15811
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.01
DomainMOD <4.13 - XSS
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
CWE-79
Aug 29, 2019
CVE-2019-13608
7.5
HIGH
KEV
RANSOMWARE
NUCLEI
EPSS 0.71
Citrix Storefront Server < 1903 - XXE
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
CWE-611
Aug 29, 2019
CVE-2019-15774
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.01
Booking < 2.5 - Open Redirect
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CWE-601
Aug 29, 2019
CVE-2019-11248
8.2
HIGH
EXPLOITED
3 PoCs
NUCLEI
EPSS 0.91
Kubernetes < 1.12.10 - Missing Authorization
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.
CWE-862
Aug 29, 2019
CVE-2019-15713
6.1
MEDIUM
NUCLEI
EPSS 0.05
MY Calendar < 3.1.10 - XSS
The my-calendar plugin before 3.1.10 for WordPress has XSS.
CWE-79
Aug 28, 2019
CVE-2019-15642
8.8
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.93
Webmin < 1.920 - Code Injection
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."
CWE-94
Aug 26, 2019
CVE-2019-15501
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.13
Lsoft Listserv < 16.5-2018a - XSS
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CWE-79
Aug 26, 2019
CVE-2019-8446
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.73
Atlassian Jira Server < 8.3.2 - Incorrect Authorization
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
CWE-863
Aug 23, 2019