Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,402 CVEs tracked 53,629 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,301 vendors 43,863 researchers
4,077 results Clear all
CVE-2018-15917 5.4 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.01
Jorani - XSS
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
CWE-79 Sep 05, 2018
CVE-2018-15745 7.5 HIGH 3 PoCs Analysis NUCLEI EPSS 0.89
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
CWE-22 Aug 30, 2018
CVE-2018-16159 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.33
Codemenschen Gift Vouchers < 2.0.1 - SQL Injection
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
CWE-89 Aug 30, 2018
CVE-2018-16133 5.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.58
Cybrotech Cybrohttpserver - Path Traversal
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
CWE-22 Aug 29, 2018
CVE-2018-15535 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.81
Tecrail Responsive Filemanager < 9.13.4 - Path Traversal
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.
CWE-22 Aug 24, 2018
CVE-2018-11776 8.1 HIGH KEV RANSOMWARE 28 PoCs Analysis NUCLEI EPSS 0.94
Apache Struts 2 Namespace Redirect OGNL Injection
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Aug 22, 2018
CVE-2018-1000226 9.8 CRITICAL NUCLEI EPSS 0.60
Cobbler <2.6.11 - Privilege Escalation
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.
CWE-732 Aug 20, 2018
CVE-2018-11511 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.20
Asustor Data Master - SQL Injection
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
CWE-89 Aug 16, 2018
CVE-2018-15138 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.53
Ericsson-LG iPECS NMS 30M - Path Traversal
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
CWE-22 Aug 15, 2018
CVE-2018-14933 9.8 CRITICAL KEV 3 PoCs Analysis NUCLEI EPSS 0.94
NUUO NVRmini - RCE
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CWE-78 Aug 04, 2018
CVE-2018-14912 7.5 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.91
CGit <1.2.1 - Path Traversal
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
CWE-22 Aug 03, 2018
CVE-2018-14728 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.91
Responsive FileManager 9.13.1 - SSRF
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
CWE-918 Aug 03, 2018
CVE-2018-14574 6.1 MEDIUM NUCLEI EPSS 0.09
Django <1.11.15, <2.0.8 - Open Redirect
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CWE-601 Aug 03, 2018
CVE-2018-14474 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Orange Forum 1.4.0 - Open Redirect
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
CWE-601 Jul 20, 2018
CVE-2018-7602 9.8 CRITICAL KEV RANSOMWARE 11 PoCs Analysis NUCLEI EPSS 0.94
Drupal < 7.59 - Code Injection
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
CWE-94 Jul 19, 2018
CVE-2018-2894 9.8 CRITICAL EXPLOITED RANSOMWARE 5 PoCs Analysis NUCLEI EPSS 0.94
Oracle WebLogic Server <12.2.1.3 - RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Jul 18, 2018
CVE-2018-13980 5.5 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.15
Zeta-producer Zeta Producer < 14.2.1 - Path Traversal
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.
CWE-22 Jul 16, 2018
CVE-2018-14064 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.77
VelotiSmart WiFi B-380 - Path Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.
CWE-22 Jul 15, 2018
CVE-2018-8024 5.4 MEDIUM NUCLEI EPSS 0.50
Apache Spark <2.3 - Open Redirect
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.
CWE-200 Jul 12, 2018
CVE-2018-7765 8.8 HIGH EXPLOITED NUCLEI EPSS 0.06
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.
CWE-89 Jul 03, 2018