Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,077 results Clear all
CVE-2017-17762 7.5 HIGH EXPLOITED NUCLEI EPSS 0.02
Episerver 7 - Blind XML External Entity Injection
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
CWE-611 Aug 29, 2018
CVE-2017-17736 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.93
Kentico - Installer Privilege Escalation
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
CWE-425 Mar 23, 2018
CVE-2017-18024 6.1 MEDIUM NUCLEI EPSS 0.12
AvantFAX 3.3.3 - Cross-Site Scripting
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
CWE-79 Jan 10, 2018
CVE-2017-8046 9.8 CRITICAL EXPLOITED RANSOMWARE 13 PoCs Analysis NUCLEI EPSS 0.94
Vmware Spring Boot < 1.5.9 - Improper Input Validation
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
CWE-20 Jan 04, 2018
CVE-2017-9965 5.8 MEDIUM NUCLEI EPSS 0.00
Schneider-electric Pelco Videoxpert < 2.1 - Path Traversal
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.
CWE-22 Jan 02, 2018
CVE-2017-17731 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.84
DedeCMS 5.7 - SQL Injection
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CWE-89 Dec 18, 2017
CVE-2017-17562 8.1 HIGH KEV 9 PoCs Analysis NUCLEI EPSS 0.94
Embedthis GoAhead <3.6.5 - Remote Code Execution
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.
Dec 12, 2017
CVE-2017-17451 6.1 MEDIUM NUCLEI EPSS 0.14
WordPress Mailster <=1.5.4 - Cross-Site Scripting
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
CWE-79 Dec 07, 2017
CVE-2017-17092 5.4 MEDIUM 1 Writeup NUCLEI EPSS 0.04
WordPress < 4.9.1 - Authenticated JavaScript File Upload
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
CWE-79 Dec 02, 2017
CVE-2017-6090 8.8 HIGH EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.87
Phpcollab < 2.5.1 - Unrestricted File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
CWE-434 Oct 03, 2017
CVE-2017-9805 8.1 HIGH KEV RANSOMWARE 28 PoCs Analysis NUCLEI EPSS 0.94
Apache Struts 2 REST Plugin XStream RCE
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
CWE-502 Sep 15, 2017
CVE-2017-3133 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.09
Fortinet Fortios < 5.6.0 - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
CWE-79 Sep 12, 2017
CVE-2017-3132 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.09
Fortinet Fortios < 5.6.0 - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.
CWE-79 Sep 12, 2017
CVE-2017-3131 5.4 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.11
Fortinet Fortios - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
CWE-79 Sep 12, 2017
CVE-2017-7855 6.1 MEDIUM NUCLEI EPSS 0.01
Icewarp Server - XSS
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
CWE-79 Aug 31, 2017
CVE-2017-9506 6.1 MEDIUM EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.29
Atlassian OAuth Plugin <1.9.12, <2.0.4 - SSRF/XSS
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
CWE-918 Aug 23, 2017
CVE-2017-9822 8.8 HIGH KEV RANSOMWARE 5 PoCs Analysis NUCLEI EPSS 0.94
DNN <9.1.1 - RCE
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
CWE-94 Jul 20, 2017
CVE-2017-9791 9.8 CRITICAL KEV 10 PoCs Analysis NUCLEI EPSS 0.94
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CWE-20 Jul 10, 2017
CVE-2017-9841 9.8 CRITICAL KEV 21 PoCs Analysis NUCLEI EPSS 0.94
PHPUnit <4.8.28, <5.6.3 - RCE
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
CWE-94 Jun 27, 2017
CVE-2017-9833 7.5 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.85
Boa 0.94.14rc21 - Code Injection
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
CWE-22 Jun 24, 2017