Vulnerabilities with Nuclei Scanner Templates
Updated 11m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2018-19136
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.00
Domainmod < 4.11.01 - XSS
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
CWE-79
Nov 09, 2018
CVE-2018-19127
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.85
Phpcms - Code Injection
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.
CWE-94
Nov 09, 2018
CVE-2018-18925
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Gogs < 0.11.66 - Remote Code Execution
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
CWE-384
Nov 04, 2018
CVE-2018-18777
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.70
Microstrategy Web - Path Traversal
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.
CWE-22
Nov 01, 2018
CVE-2018-18775
6.1
MEDIUM
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.16
Microstrategy Web - XSS
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
CWE-79
Nov 01, 2018
CVE-2018-11759
7.5
HIGH
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Tomcat JK Connector < 1.2.44 - Path Traversal
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
CWE-22
Oct 31, 2018
CVE-2018-18778
6.5
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.93
Acme Mini-httpd < 1.30 - Information Disclosure
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
CWE-200
Oct 29, 2018
CVE-2018-18608
6.1
MEDIUM
NUCLEI
EPSS 0.08
Dedecms - XSS
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.
CWE-79
Oct 23, 2018
CVE-2018-12675
6.1
MEDIUM
NUCLEI
EPSS 0.09
SV3C HD Camera - SSRF
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.
CWE-601
Oct 19, 2018
CVE-2018-10823
8.8
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.94
Dlink Dwr-116 Firmware < 1.06 - OS Command Injection
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
CWE-78
Oct 17, 2018
CVE-2018-10822
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.86
Dlink Dwr-116 Firmware < 1.06 - Path Traversal
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /.. or // after "GET /uir" in an HTTP request. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-6190.
CWE-22
Oct 17, 2018
CVE-2018-3238
6.9
MEDIUM
NUCLEI
EPSS 0.30
Oracle WebCenter Sites 11.1.1.8.0 - RCE
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 6.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N).
Oct 17, 2018
CVE-2018-3167
5.3
MEDIUM
NUCLEI
EPSS 0.68
Oracle E-Business Suite <12.2.8 - Info Disclosure
Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Management Pack for Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Application Management Pack for Oracle E-Business Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Oct 17, 2018
CVE-2018-18323
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.86
Webpanel - Path Traversal
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.
CWE-22
Oct 15, 2018
CVE-2018-10141
6.1
MEDIUM
NUCLEI
EPSS 0.44
Palo Alto Networks PAN-OS <8.1.4 - XSS
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
CWE-79
Oct 12, 2018
CVE-2018-9206
9.8
CRITICAL
EXPLOITED
12 PoCs
Analysis
NUCLEI
EPSS 0.94
Blueimp jQuery-File-Upload <=9.22.0 - File Upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
CWE-434
Oct 11, 2018
CVE-2018-12455
8.1
HIGH
NUCLEI
EPSS 0.19
Intelbras NPLUG 1.0.0.14 - Auth Bypass
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie.
CWE-287
Oct 10, 2018
CVE-2018-8006
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.80
Apache ActiveMQ <5.15.5 - XSS
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
CWE-79
Oct 10, 2018
CVE-2018-18069
6.1
MEDIUM
NUCLEI
EPSS 0.14
Wpml < 3.6.3 - XSS
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
CWE-79
Oct 08, 2018
CVE-2018-11784
4.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.83
Apache Tomcat < 7.0.90 - Open Redirect
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
CWE-601
Oct 04, 2018