Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2018-11133
6.1
MEDIUM
NUCLEI
EPSS 0.00
Quest Kace System Management Appliance - XSS
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
CWE-79
May 31, 2018
CVE-2018-11473
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.00
Monstra - XSS
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
CWE-79
May 25, 2018
CVE-2018-11231
8.1
HIGH
NUCLEI
EPSS 0.77
Divido - SQL Injection
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
CWE-89
May 23, 2018
CVE-2018-10095
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.47
Dolibarr <7.0.2 - XSS
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
CWE-79
May 22, 2018
CVE-2018-10738
7.2
HIGH
NUCLEI
EPSS 0.67
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
CWE-89
May 16, 2018
CVE-2018-10737
7.2
HIGH
EXPLOITED
NUCLEI
EPSS 0.83
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
CWE-89
May 16, 2018
CVE-2018-10736
7.2
HIGH
NUCLEI
EPSS 0.83
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
CWE-89
May 16, 2018
CVE-2018-10735
7.2
HIGH
NUCLEI
EPSS 0.86
Nagios XI < 5.2.9 - SQL Injection
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
CWE-89
May 16, 2018
CVE-2018-5230
6.1
MEDIUM
NUCLEI
EPSS 0.23
Atlassian Jira <7.6.6, <7.7.0-7.7.4, <7.8.0-7.8.4, <7.9.0-7.9.2 - XSS
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.
CWE-79
May 14, 2018
CVE-2018-10942
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.86
Attribute Wizard - Unrestricted File Upload
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
CWE-434
May 10, 2018
CVE-2018-10562
9.8
CRITICAL
KEV
RANSOMWARE
9 PoCs
Analysis
NUCLEI
EPSS 0.94
Dasan GPON - Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
CWE-78
May 04, 2018
CVE-2018-9845
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.60
Etherpad Lite <1.6.4 - Privilege Escalation
Etherpad Lite before 1.6.4 is exploitable for admin access.
CWE-178
Apr 29, 2018
CVE-2018-1335
8.1
HIGH
EXPLOITED
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Tika <1.18 - Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Apr 25, 2018
CVE-2018-10245
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.00
AWStats <7.6 - Info Disclosure
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
CWE-200
Apr 20, 2018
CVE-2018-10201
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.81
NComputing vSpace Pro <11 - Info Disclosure
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
CWE-22
Apr 20, 2018
CVE-2018-10230
6.1
MEDIUM
NUCLEI
EPSS 0.03
Zend Server <9.1.3 - XSS
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
CWE-79
Apr 19, 2018
CVE-2018-2791
8.2
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.87
Oracle WebCenter Sites <12.2.1.3.0 - Info Disclosure
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Apr 19, 2018
CVE-2018-9118
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.71
99robots WP Background Takeover Advertisements - Path Traversal
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
CWE-22
Apr 12, 2018
CVE-2018-1273
9.8
CRITICAL
KEV
RANSOMWARE
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Pivotal Software Spring Data Commons < 1.12.10 - Code Injection
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
CWE-94
Apr 11, 2018
CVE-2018-9995
9.8
CRITICAL
EXPLOITED
RANSOMWARE
33 PoCs
Analysis
NUCLEI
EPSS 0.94
TBK DVR4104/DVR4216 - Auth Bypass
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
Apr 10, 2018