Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
4,077 results Clear all
CVE-2015-9406 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.87
Mtheme-unus < 2.3 - Path Traversal
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
CWE-22 Sep 20, 2019
CVE-2015-9323 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.76
Duckdev 404 TO 301 < 2.0.3 - SQL Injection
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
CWE-89 Aug 16, 2019
CVE-2015-9312 6.1 MEDIUM NUCLEI EPSS 0.02
Newstatpress < 1.0.5 - XSS
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
CWE-79 Aug 14, 2019
CVE-2015-4632 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.78
Koha < 3.14.16 - Path Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
CWE-22 Oct 18, 2018
CVE-2015-1503 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.92
IceWarp Mail Server <11.2 - Path Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
CWE-22 May 08, 2018
CVE-2015-6544 6.1 MEDIUM NUCLEI EPSS 0.28
Combodo Itop < 2.2.0-2459 - XSS
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.
CWE-79 Feb 20, 2018
CVE-2015-4668 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.04
Xceedium Xsuite - Open Redirect
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
CWE-601 Sep 25, 2017
CVE-2015-4074 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.86
Helpdesk Pro < 1.3.0 - Path Traversal
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
CWE-22 Sep 20, 2017
CVE-2015-8350 6.1 MEDIUM NUCLEI EPSS 0.00
WordPress Calls to Action <2.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.
CWE-79 Sep 11, 2017
CVE-2015-8349 6.1 MEDIUM NUCLEI EPSS 0.10
SourceBans <2.0 - XSS
Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.
CWE-79 Sep 11, 2017
CVE-2015-7780 6.5 MEDIUM NUCLEI EPSS 0.36
ManageEngine Firewall Analyzer <8.0 - Path Traversal
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CWE-22 Jun 27, 2017
CVE-2015-5469 7.5 HIGH NUCLEI EPSS 0.49
MDC YouTube Downloader <2.1.0 - Path Traversal
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
CWE-22 May 23, 2017
CVE-2015-4455 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.80
Aviary Image Editor Add-on For Gravit... - Unrestricted File Upload
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.
CWE-434 May 23, 2017
CVE-2015-7245 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.89
D-link Dvg-n5402sp Firmware - Path Traversal
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.
CWE-22 Apr 24, 2017
CVE-2015-8813 8.2 HIGH EXPLOITED NUCLEI EPSS 0.83
Umbraco < 7.3.8 - SSRF
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
CWE-918 Mar 03, 2017
CVE-2015-2794 9.8 CRITICAL 3 PoCs Analysis NUCLEI EPSS 0.92
Dotnetnuke < 07.04.00 - Access Control
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
CWE-264 Feb 06, 2017
CVE-2015-2080 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.92
Fedora < 9.2.9.v20150224 - Information Disclosure
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
CWE-200 Oct 07, 2016
CVE-2015-1000012 7.5 HIGH NUCLEI EPSS 0.69
mypixs v0.3 - Path Traversal
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
CWE-200 Oct 06, 2016
CVE-2015-1000010 7.5 HIGH NUCLEI EPSS 0.32
simple-image-manipulator <1.0 - Info Disclosure
Remote file download in simple-image-manipulator v1.0 wordpress plugin
CWE-284 Oct 06, 2016
CVE-2015-1000005 7.5 HIGH NUCLEI EPSS 0.21
Candidate Application Form <1.0 - RCE
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
CWE-22 Oct 06, 2016