Vulnerabilities with Nuclei Scanner Templates

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,402 CVEs tracked 53,629 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,301 vendors 43,863 researchers
4,077 results Clear all
CVE-2018-11133 6.1 MEDIUM NUCLEI EPSS 0.00
Quest Kace System Management Appliance - XSS
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
CWE-79 May 31, 2018
CVE-2018-11473 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.00
Monstra - XSS
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
CWE-79 May 25, 2018
CVE-2018-11231 8.1 HIGH NUCLEI EPSS 0.77
Divido - SQL Injection
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
CWE-89 May 23, 2018
CVE-2018-10095 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.47
Dolibarr <7.0.2 - XSS
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
CWE-79 May 22, 2018
CVE-2018-10738 7.2 HIGH NUCLEI EPSS 0.67
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
CWE-89 May 16, 2018
CVE-2018-10737 7.2 HIGH EXPLOITED NUCLEI EPSS 0.83
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
CWE-89 May 16, 2018
CVE-2018-10736 7.2 HIGH NUCLEI EPSS 0.83
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
CWE-89 May 16, 2018
CVE-2018-10735 7.2 HIGH NUCLEI EPSS 0.86
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
CWE-89 May 16, 2018
CVE-2018-5230 6.1 MEDIUM NUCLEI EPSS 0.23
Atlassian Jira <7.6.6, <7.7.0-7.7.4, <7.8.0-7.8.4, <7.9.0-7.9.2 - XSS
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.
CWE-79 May 14, 2018
CVE-2018-10942 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.86
Attribute Wizard - Unrestricted File Upload
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
CWE-434 May 10, 2018
CVE-2018-10562 9.8 CRITICAL KEV RANSOMWARE 9 PoCs Analysis NUCLEI EPSS 0.94
Dasan GPON - Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
CWE-78 May 04, 2018
CVE-2018-9845 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.60
Etherpad Lite <1.6.4 - Privilege Escalation
Etherpad Lite before 1.6.4 is exploitable for admin access.
CWE-178 Apr 29, 2018
CVE-2018-1335 8.1 HIGH EXPLOITED 8 PoCs Analysis NUCLEI EPSS 0.94
Apache Tika <1.18 - Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Apr 25, 2018
CVE-2018-10245 5.3 MEDIUM 1 Writeup NUCLEI EPSS 0.00
AWStats <7.6 - Info Disclosure
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
CWE-200 Apr 20, 2018
CVE-2018-10201 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.81
NComputing vSpace Pro <11 - Info Disclosure
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
CWE-22 Apr 20, 2018
CVE-2018-10230 6.1 MEDIUM NUCLEI EPSS 0.03
Zend Server <9.1.3 - XSS
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
CWE-79 Apr 19, 2018
CVE-2018-2791 8.2 HIGH 1 PoC Analysis NUCLEI EPSS 0.87
Oracle WebCenter Sites <12.2.1.3.0 - Info Disclosure
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Apr 19, 2018
CVE-2018-9118 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.71
99robots WP Background Takeover Advertisements - Path Traversal
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
CWE-22 Apr 12, 2018
CVE-2018-1273 9.8 CRITICAL KEV RANSOMWARE 10 PoCs Analysis NUCLEI EPSS 0.94
Pivotal Software Spring Data Commons < 1.12.10 - Code Injection
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
CWE-94 Apr 11, 2018
CVE-2018-9995 9.8 CRITICAL EXPLOITED RANSOMWARE 33 PoCs Analysis NUCLEI EPSS 0.94
TBK DVR4104/DVR4216 - Auth Bypass
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
Apr 10, 2018