Vulnerabilities with Nuclei Scanner Templates
Updated 33m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2013-3827
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.92
Oracle GlassFish Server <12.1.2 - Info Disclosure
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.
Oct 16, 2013
CVE-2013-5528
1 PoC
Analysis
NUCLEI
EPSS 0.62
Cisco Unified Communications Manager - Path Traversal
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.
CWE-22
Oct 11, 2013
CVE-2013-5979
1 PoC
Analysis
NUCLEI
EPSS 0.35
Xibo - Path Traversal
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.
CWE-22
Oct 02, 2013
CVE-2013-4625
1 PoC
Analysis
NUCLEI
EPSS 0.06
WordPress Duplicator <0.4.5 - XSS
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.
CWE-79
Aug 09, 2013
CVE-2013-2251
9.8
CRITICAL
KEV
5 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache Archiva < 1.3.8 - Injection
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CWE-74
Jul 20, 2013
CVE-2013-2248
1 PoC
Analysis
NUCLEI
EPSS 0.92
Apache Struts < 2.3.15.1 - Improper Input Validation
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
CWE-20
Jul 20, 2013
CVE-2013-4117
1 PoC
Analysis
NUCLEI
EPSS 0.12
Anshul Sharma Category-grid-view-gallery - XSS
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
CWE-79
Jul 16, 2013
CVE-2013-1965
1 PoC
Analysis
NUCLEI
EPSS 0.92
Apache Struts < 2.3.14.1 - Code Injection
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
CWE-94
Jul 10, 2013
CVE-2013-3526
1 PoC
Analysis
NUCLEI
EPSS 0.08
Trafficanalyzer - XSS
Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.
CWE-79
May 10, 2013
CVE-2012-2122
6 PoCs
Analysis
NUCLEI
EPSS 0.94
Oracle Mysql - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
CWE-287
Jun 26, 2012
CVE-2012-10018
8.3
HIGH
EXPLOITED
NUCLEI
EPSS 0.03
Mapplic & Mapplic Lite <6.1-1.0 - SSRF
The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.
CWE-918
Oct 16, 2024
CVE-2012-4768
1 PoC
Analysis
NUCLEI
EPSS 0.02
WordPress Download Monitor <3.3.5.9 - XSS
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
CWE-79
Sep 04, 2014
CVE-2012-6499
2 PoCs
Analysis
NUCLEI
EPSS 0.46
Age Verification < 0.4 - Improper Input Validation
Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.
CWE-20
Jan 12, 2013
CVE-2012-4982
1 PoC
Analysis
NUCLEI
EPSS 0.09
Forescout CounterACT <7.0 - Open Redirect
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
CWE-20
Dec 05, 2012
CVE-2012-5913
1 PoC
Analysis
NUCLEI
EPSS 0.01
Wordpress Integrator - XSS
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.
CWE-79
Nov 17, 2012
CVE-2012-4940
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.80
Axigen Free Mail Server - Path Traversal
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.
CWE-22
Oct 31, 2012
CVE-2012-4547
NUCLEI
EPSS 0.32
AWStats <7.1 - Unknown Vuln
Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.
CWE-79
Oct 31, 2012
CVE-2012-3153
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.91
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.
Oct 16, 2012
CVE-2012-5321
2 PoCs
Analysis
NUCLEI
EPSS 0.23
TikiWiki CMS/Groupware 8.3 - XSS
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."
CWE-20
Oct 08, 2012
CVE-2012-4242
1 PoC
Analysis
NUCLEI
EPSS 0.08
MF Gig Calendar - XSS
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
CWE-79
Oct 01, 2012