Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2017-18528
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress pdf-print <1.9.4 - XSS
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
CWE-79
Aug 20, 2019
CVE-2017-18527
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress <1.0.7 - XSS
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
CWE-79
Aug 20, 2019
CVE-2017-18518
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress <1.1.0 - XSS
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
CWE-79
Aug 20, 2019
CVE-2017-18517
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress bws-pinterest <1.0.5 - XSS
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
CWE-79
Aug 20, 2019
CVE-2017-18542
6.1
MEDIUM
NUCLEI
EPSS 0.00
Zendesk-Help-Center <1.0.5 - XSS
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
CWE-79
Aug 16, 2019
CVE-2017-18487
6.1
MEDIUM
NUCLEI
EPSS 0.00
AdPush < 1.44 - Cross-Site Scripting
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18496
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress htaccess <1.7.6 - XSS
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18494
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress <1.36 - XSS
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18493
6.1
MEDIUM
NUCLEI
EPSS 0.00
Bestwebsoft Custom Admin Page < 0.1.2 - XSS
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18492
6.1
MEDIUM
NUCLEI
EPSS 0.00
Bestwebsoft Contact Form TO DB < 1.5.7 - XSS
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18491
6.1
MEDIUM
NUCLEI
EPSS 0.00
Bestwebsoft Contact Form < 4.0.6 - XSS
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18490
6.1
MEDIUM
NUCLEI
EPSS 0.00
Bestwebsoft Contact Form Multi < 1.2.1 - XSS
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
CWE-79
Aug 13, 2019
CVE-2017-18505
6.1
MEDIUM
NUCLEI
EPSS 0.03
Twitter-plugin <2.55 - XSS
The twitter-plugin plugin before 2.55 for WordPress has XSS.
CWE-79
Aug 12, 2019
CVE-2017-18502
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress Subscriber Plugin <1.3.5 - XSS
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.
CWE-79
Aug 12, 2019
CVE-2017-18501
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress social-login-bws <0.2 - XSS
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.
CWE-79
Aug 12, 2019
CVE-2017-18500
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress <1.1.1 - XSS
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
CWE-79
Aug 12, 2019
CVE-2017-8229
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.93
Amcrest Ipm-721s Firmware - Credentials Management
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in IDA pro is identified to be setting up the configuration for the device. If one scrolls to the address 0x000437C2 then one can see that /current_config is being set as an ALIAS for /mnt/mtd/Config folder on the device. If one TELNETs into the device and navigates to /mnt/mtd/Config folder, one can observe that it contains various files such as Account1, Account2, SHAACcount1, etc. This means that if one navigates to http://[IPofcamera]/current_config/Sha1Account1 then one should be able to view the content of the files. The security researchers assumed that this was only possible only after authentication to the device. However, when unauthenticated access tests were performed for the same URL as provided above, it was observed that the device file could be downloaded without any authentication.
CWE-255
Jul 03, 2019
CVE-2017-5871
5.4
MEDIUM
NUCLEI
EPSS 0.03
Odoo - Open Redirect
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
CWE-601
May 22, 2019
CVE-2017-18362
9.8
CRITICAL
KEV
RANSOMWARE
1 PoC
1 Writeup
NUCLEI
EPSS 0.80
Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code Execution
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
CWE-89
Feb 05, 2019
CVE-2017-18349
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
Fastjson Insecure Deserialization - Remote Code Execution
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
CWE-20
Oct 23, 2018