Vulnerabilities with Nuclei Scanner Templates

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
4,077 results Clear all
CVE-2014-1841 1 PoC Analysis NUCLEI EPSS 0.04
Titan FTP Server <10.40.1829 - Path Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.
CWE-22 Apr 29, 2014
CVE-2014-9617 6.1 MEDIUM NUCLEI EPSS 0.26
Netsweeper <4.0.5 - Open Redirect
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
CWE-601 Feb 19, 2020
CVE-2014-9615 6.1 MEDIUM NUCLEI EPSS 0.16
Netsweeper 4.0.4 - XSS
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php.
CWE-79 Feb 19, 2020
CVE-2014-9614 9.8 CRITICAL NUCLEI EPSS 0.70
Netsweeper <4.0.5 - Info Disclosure
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
CWE-798 Feb 19, 2020
CVE-2014-9609 5.3 MEDIUM NUCLEI EPSS 0.31
Netsweeper <3.1.10, <4.0.9, <4.1.2 - Path Traversal
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.
CWE-22 Feb 19, 2020
CVE-2014-9608 6.1 MEDIUM NUCLEI EPSS 0.26
Netsweeper <4.1.2 - XSS
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Feb 19, 2020
CVE-2014-9607 6.1 MEDIUM NUCLEI EPSS 0.09
Netsweeper 4.0.3-4.0.4 - XSS
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Feb 19, 2020
CVE-2014-9606 6.1 MEDIUM NUCLEI EPSS 0.09
Netsweeper <3.1.10, 4.0.x <4.0.9, 4.1.x <4.1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2) customctid parameter to webadmin/policy/category_table_ajax.php, (3) urllist parameter to webadmin/alert/alert.php, (4) QUERY_STRING to webadmin/ajaxfilemanager/ajax_get_file_listing.php, or (5) PATH_INFO to webadmin/policy/policy_table_ajax.php/.
CWE-79 Feb 19, 2020
CVE-2014-8739 9.8 CRITICAL EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.92
jQuery File Upload Plugin <6.4.4 - RCE
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.
CWE-434 Feb 08, 2020
CVE-2014-4561 6.1 MEDIUM NUCLEI EPSS 0.13
WordPress 1.0 - XSS
The ultimate-weather plugin 1.0 for WordPress has XSS
CWE-79 Jan 10, 2020
CVE-2014-4550 6.1 MEDIUM NUCLEI EPSS 0.03
Shortcode Ninja <1.4 - XSS
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.
CWE-79 Dec 27, 2019
CVE-2014-4536 6.1 MEDIUM NUCLEI EPSS 0.03
Gravity Forms <1.5.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
CWE-79 Dec 27, 2019
CVE-2014-4535 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.04
WordPress <0.1 - XSS
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
CWE-79 Dec 27, 2019
CVE-2014-4558 6.1 MEDIUM NUCLEI EPSS 0.04
Swipe Checkout for WooCommerce <2.7.1 - XSS
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
CWE-79 Dec 27, 2019
CVE-2014-4544 6.1 MEDIUM NUCLEI EPSS 0.03
WordPress Podcast Channels <0.20 - XSS
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.
CWE-79 Dec 27, 2019
CVE-2014-4539 6.1 MEDIUM NUCLEI EPSS 0.02
WordPress Movies <0.6 - XSS
Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
CWE-79 Dec 27, 2019
CVE-2014-4592 6.1 MEDIUM NUCLEI EPSS 0.04
WP-Planet <0.1 - XSS
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CWE-79 Dec 27, 2019
CVE-2014-3206 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.92
Seagate Blackarmor Nas 220 Firmware - Improper Input Validation
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
CWE-20 Feb 23, 2018
CVE-2014-1203 9.8 CRITICAL NUCLEI EPSS 0.56
Eyou < 3.6 - Command Injection
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
CWE-77 Oct 24, 2017
CVE-2014-3744 7.5 HIGH 1 PoC 1 Writeup Analysis NUCLEI EPSS 0.78
Nodejs Node.js < 0.2.4 - Path Traversal
Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
CWE-22 Oct 23, 2017