Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2017-17762
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.02
Episerver 7 - Blind XML External Entity Injection
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
CWE-611
Aug 29, 2018
CVE-2017-17736
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.93
Kentico - Installer Privilege Escalation
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
CWE-425
Mar 23, 2018
CVE-2017-18024
6.1
MEDIUM
NUCLEI
EPSS 0.12
AvantFAX 3.3.3 - Cross-Site Scripting
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
CWE-79
Jan 10, 2018
CVE-2017-8046
9.8
CRITICAL
EXPLOITED
RANSOMWARE
13 PoCs
Analysis
NUCLEI
EPSS 0.94
Vmware Spring Boot < 1.5.9 - Improper Input Validation
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
CWE-20
Jan 04, 2018
CVE-2017-9965
5.8
MEDIUM
NUCLEI
EPSS 0.00
Schneider-electric Pelco Videoxpert < 2.1 - Path Traversal
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.
CWE-22
Jan 02, 2018
CVE-2017-17731
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.84
DedeCMS 5.7 - SQL Injection
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CWE-89
Dec 18, 2017
CVE-2017-17562
8.1
HIGH
KEV
9 PoCs
Analysis
NUCLEI
EPSS 0.94
Embedthis GoAhead <3.6.5 - Remote Code Execution
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.
Dec 12, 2017
CVE-2017-17451
6.1
MEDIUM
NUCLEI
EPSS 0.14
WordPress Mailster <=1.5.4 - Cross-Site Scripting
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
CWE-79
Dec 07, 2017
CVE-2017-17092
5.4
MEDIUM
1 Writeup
NUCLEI
EPSS 0.04
WordPress < 4.9.1 - Authenticated JavaScript File Upload
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
CWE-79
Dec 02, 2017
CVE-2017-6090
8.8
HIGH
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.87
Phpcollab < 2.5.1 - Unrestricted File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
CWE-434
Oct 03, 2017
CVE-2017-9805
8.1
HIGH
KEV
RANSOMWARE
28 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Struts 2 REST Plugin XStream RCE
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
CWE-502
Sep 15, 2017
CVE-2017-3133
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.09
Fortinet Fortios < 5.6.0 - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
CWE-79
Sep 12, 2017
CVE-2017-3132
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.09
Fortinet Fortios < 5.6.0 - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.
CWE-79
Sep 12, 2017
CVE-2017-3131
5.4
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.11
Fortinet Fortios - XSS
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
CWE-79
Sep 12, 2017
CVE-2017-7855
6.1
MEDIUM
NUCLEI
EPSS 0.01
Icewarp Server - XSS
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
CWE-79
Aug 31, 2017
CVE-2017-9506
6.1
MEDIUM
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.29
Atlassian OAuth Plugin <1.9.12, <2.0.4 - SSRF/XSS
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
CWE-918
Aug 23, 2017
CVE-2017-9822
8.8
HIGH
KEV
RANSOMWARE
5 PoCs
Analysis
NUCLEI
EPSS 0.94
DNN <9.1.1 - RCE
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
CWE-94
Jul 20, 2017
CVE-2017-9791
9.8
CRITICAL
KEV
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CWE-20
Jul 10, 2017
CVE-2017-9841
9.8
CRITICAL
KEV
21 PoCs
Analysis
NUCLEI
EPSS 0.94
PHPUnit <4.8.28, <5.6.3 - RCE
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
CWE-94
Jun 27, 2017
CVE-2017-9833
7.5
HIGH
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.85
Boa 0.94.14rc21 - Code Injection
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
CWE-22
Jun 24, 2017