Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2014-1841
1 PoC
Analysis
NUCLEI
EPSS 0.04
Titan FTP Server <10.40.1829 - Path Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.
CWE-22
Apr 29, 2014
CVE-2014-9617
6.1
MEDIUM
NUCLEI
EPSS 0.26
Netsweeper <4.0.5 - Open Redirect
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
CWE-601
Feb 19, 2020
CVE-2014-9615
6.1
MEDIUM
NUCLEI
EPSS 0.16
Netsweeper 4.0.4 - XSS
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php.
CWE-79
Feb 19, 2020
CVE-2014-9614
9.8
CRITICAL
NUCLEI
EPSS 0.70
Netsweeper <4.0.5 - Info Disclosure
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
CWE-798
Feb 19, 2020
CVE-2014-9609
5.3
MEDIUM
NUCLEI
EPSS 0.31
Netsweeper <3.1.10, <4.0.9, <4.1.2 - Path Traversal
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.
CWE-22
Feb 19, 2020
CVE-2014-9608
6.1
MEDIUM
NUCLEI
EPSS 0.26
Netsweeper <4.1.2 - XSS
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79
Feb 19, 2020
CVE-2014-9607
6.1
MEDIUM
NUCLEI
EPSS 0.09
Netsweeper 4.0.3-4.0.4 - XSS
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79
Feb 19, 2020
CVE-2014-9606
6.1
MEDIUM
NUCLEI
EPSS 0.09
Netsweeper <3.1.10, 4.0.x <4.0.9, 4.1.x <4.1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2) customctid parameter to webadmin/policy/category_table_ajax.php, (3) urllist parameter to webadmin/alert/alert.php, (4) QUERY_STRING to webadmin/ajaxfilemanager/ajax_get_file_listing.php, or (5) PATH_INFO to webadmin/policy/policy_table_ajax.php/.
CWE-79
Feb 19, 2020
CVE-2014-8739
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.92
jQuery File Upload Plugin <6.4.4 - RCE
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
CWE-434
Feb 08, 2020
CVE-2014-4561
6.1
MEDIUM
NUCLEI
EPSS 0.13
WordPress 1.0 - XSS
The ultimate-weather plugin 1.0 for WordPress has XSS
CWE-79
Jan 10, 2020
CVE-2014-4550
6.1
MEDIUM
NUCLEI
EPSS 0.03
Shortcode Ninja <1.4 - XSS
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.
CWE-79
Dec 27, 2019
CVE-2014-4536
6.1
MEDIUM
NUCLEI
EPSS 0.03
Gravity Forms <1.5.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
CWE-79
Dec 27, 2019
CVE-2014-4535
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.04
WordPress <0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
CWE-79
Dec 27, 2019
CVE-2014-4558
6.1
MEDIUM
NUCLEI
EPSS 0.04
Swipe Checkout for WooCommerce <2.7.1 - XSS
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
CWE-79
Dec 27, 2019
CVE-2014-4544
6.1
MEDIUM
NUCLEI
EPSS 0.03
WordPress Podcast Channels <0.20 - XSS
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.
CWE-79
Dec 27, 2019
CVE-2014-4539
6.1
MEDIUM
NUCLEI
EPSS 0.02
WordPress Movies <0.6 - XSS
Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
CWE-79
Dec 27, 2019
CVE-2014-4592
6.1
MEDIUM
NUCLEI
EPSS 0.04
WP-Planet <0.1 - XSS
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79
Dec 27, 2019
CVE-2014-3206
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Seagate Blackarmor Nas 220 Firmware - Improper Input Validation
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
CWE-20
Feb 23, 2018
CVE-2014-1203
9.8
CRITICAL
NUCLEI
EPSS 0.56
Eyou < 3.6 - Command Injection
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
CWE-77
Oct 24, 2017
CVE-2014-3744
7.5
HIGH
1 PoC
1 Writeup
Analysis
NUCLEI
EPSS 0.78
Nodejs Node.js < 0.2.4 - Path Traversal
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
CWE-22
Oct 23, 2017