Vulnerabilities with Nuclei Scanner Templates
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2015-9406
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.87
Mtheme-unus < 2.3 - Path Traversal
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
CWE-22
Sep 20, 2019
CVE-2015-9323
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.76
Duckdev 404 TO 301 < 2.0.3 - SQL Injection
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
CWE-89
Aug 16, 2019
CVE-2015-9312
6.1
MEDIUM
NUCLEI
EPSS 0.02
Newstatpress < 1.0.5 - XSS
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
CWE-79
Aug 14, 2019
CVE-2015-4632
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.78
Koha < 3.14.16 - Path Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
CWE-22
Oct 18, 2018
CVE-2015-1503
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.92
IceWarp Mail Server <11.2 - Path Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
CWE-22
May 08, 2018
CVE-2015-6544
6.1
MEDIUM
NUCLEI
EPSS 0.28
Combodo Itop < 2.2.0-2459 - XSS
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.
CWE-79
Feb 20, 2018
CVE-2015-4668
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.04
Xceedium Xsuite - Open Redirect
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
CWE-601
Sep 25, 2017
CVE-2015-4074
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.86
Helpdesk Pro < 1.3.0 - Path Traversal
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
CWE-22
Sep 20, 2017
CVE-2015-8350
6.1
MEDIUM
NUCLEI
EPSS 0.00
WordPress Calls to Action <2.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.
CWE-79
Sep 11, 2017
CVE-2015-8349
6.1
MEDIUM
NUCLEI
EPSS 0.10
SourceBans <2.0 - XSS
Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.
CWE-79
Sep 11, 2017
CVE-2015-7780
6.5
MEDIUM
NUCLEI
EPSS 0.36
ManageEngine Firewall Analyzer <8.0 - Path Traversal
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CWE-22
Jun 27, 2017
CVE-2015-5469
7.5
HIGH
NUCLEI
EPSS 0.49
MDC YouTube Downloader <2.1.0 - Path Traversal
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
CWE-22
May 23, 2017
CVE-2015-4455
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.80
Aviary Image Editor Add-on For Gravit... - Unrestricted File Upload
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.
CWE-434
May 23, 2017
CVE-2015-7245
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.89
D-link Dvg-n5402sp Firmware - Path Traversal
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.
CWE-22
Apr 24, 2017
CVE-2015-8813
8.2
HIGH
EXPLOITED
NUCLEI
EPSS 0.83
Umbraco < 7.3.8 - SSRF
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
CWE-918
Mar 03, 2017
CVE-2015-2794
9.8
CRITICAL
3 PoCs
Analysis
NUCLEI
EPSS 0.92
Dotnetnuke < 07.04.00 - Access Control
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
CWE-264
Feb 06, 2017
CVE-2015-2080
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.92
Fedora < 9.2.9.v20150224 - Information Disclosure
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
CWE-200
Oct 07, 2016
CVE-2015-1000012
7.5
HIGH
NUCLEI
EPSS 0.69
mypixs v0.3 - Path Traversal
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
CWE-200
Oct 06, 2016
CVE-2015-1000010
7.5
HIGH
NUCLEI
EPSS 0.32
simple-image-manipulator <1.0 - Info Disclosure
Remote file download in simple-image-manipulator v1.0 wordpress plugin
CWE-284
Oct 06, 2016
CVE-2015-1000005
7.5
HIGH
NUCLEI
EPSS 0.21
Candidate Application Form <1.0 - RCE
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
CWE-22
Oct 06, 2016