Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
4,077 results Clear all
CVE-2018-25114 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.73
osCommerce Online Merchant <2.3.4.1 - RCE
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application later includes this file, the injected payload is executed, resulting in full server-side compromise.
CWE-434 Jul 23, 2025
CVE-2018-7282 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.69
Titool Printmonitor < pm18.2.1 - SQL Injection
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.
CWE-89 Dec 06, 2019
CVE-2018-20985 9.8 CRITICAL NUCLEI EPSS 0.43
WP Payeezy Pay < 2.98 - Improper Input Validation
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
CWE-20 Aug 22, 2019
CVE-2018-19386 6.1 MEDIUM NUCLEI EPSS 0.23
SolarWinds Database Performance Analyzer 11.1.457 - XSS
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
CWE-79 Aug 14, 2019
CVE-2018-18570 6.1 MEDIUM NUCLEI EPSS 0.11
Planon < 41 - XSS
Planon before Live Build 41 has XSS.
CWE-79 Jul 29, 2019
CVE-2018-18325 7.5 HIGH KEV 2 PoCs Analysis NUCLEI EPSS 0.93
Dnnsoftware Dotnetnuke < 9.2.2 - Weak Encryption
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
CWE-326 Jul 03, 2019
CVE-2018-15811 7.5 HIGH KEV 2 PoCs Analysis NUCLEI EPSS 0.93
Dnnsoftware Dotnetnuke < 9.2.1 - Weak Encryption
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
CWE-326 Jul 03, 2019
CVE-2018-11686 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Flowpaper Flexpaper < 2.3.6 - Improper Input Validation
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
CWE-20 Jul 03, 2019
CVE-2018-11227 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.02
Monstra Cms < 3.0.4 - XSS
Monstra CMS 3.0.4 and earlier has XSS via index.php.
CWE-79 Jul 03, 2019
CVE-2018-14918 7.5 HIGH EXPLOITED NUCLEI EPSS 0.73
LOYTEC LGATE-902 <6.3.2 - Path Traversal
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
CWE-22 Jun 28, 2019
CVE-2018-14916 9.1 CRITICAL NUCLEI EPSS 0.68
LOYTEC LGATE-902 <6.3.2 - Info Disclosure
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
CWE-732 Jun 28, 2019
CVE-2018-20470 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.82
Sahipro Sahi Pro < 8.0.0 - Path Traversal
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.
CWE-22 Jun 17, 2019
CVE-2018-13380 4.7 MEDIUM NUCLEI EPSS 0.23
Fortinet Fortios < 5.2 - XSS
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
CWE-79 Jun 04, 2019
CVE-2018-13379 9.1 CRITICAL KEV RANSOMWARE 14 PoCs Analysis NUCLEI EPSS 0.94
Fortinet Fortiproxy < 1.2.9 - Path Traversal
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
CWE-22 Jun 04, 2019
CVE-2018-14013 6.1 MEDIUM NUCLEI EPSS 0.23
Synacor Zimbra Collaboration Suite <8.8.11 - XSS
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
CWE-79 May 29, 2019
CVE-2018-7841 9.8 CRITICAL KEV 1 PoC Analysis NUCLEI EPSS 0.55
U.motion Builder <1.3.4 - SQL Injection
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
CWE-89 May 22, 2019
CVE-2018-16139 6.1 MEDIUM NUCLEI EPSS 0.01
Bibliosoft Bibliopac - XSS
Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web script or HTML via the db or action parameter to to bin/wxis.exe/bibliopac/.
CWE-79 May 13, 2019
CVE-2018-12300 6.1 MEDIUM NUCLEI EPSS 0.16
Seagate NAS OS <4.3.15.1 - Info Disclosure
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
CWE-601 May 13, 2019
CVE-2018-12296 7.5 HIGH EXPLOITED NUCLEI EPSS 0.73
Seagate NAS OS <4.3.15.1 - Info Disclosure
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
CWE-732 May 13, 2019
CVE-2018-20824 6.1 MEDIUM NUCLEI EPSS 0.11
Atlassian Jira < 7.13.1 - XSS
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
CWE-79 May 03, 2019