Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2011-3600
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.66
OFBiz <16.11.04 - SSRF
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
CWE-611
Nov 26, 2019
CVE-2011-4624
NUCLEI
EPSS 0.06
Codeasily Grand Flagallery < 1.56 - XSS
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
CWE-79
Oct 01, 2014
CVE-2011-5265
1 PoC
Analysis
NUCLEI
EPSS 0.06
Featurific FOR Wordpress Featurific-for-wordpress - XSS
Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.
CWE-79
Feb 12, 2013
CVE-2011-4618
1 PoC
Analysis
NUCLEI
EPSS 0.05
Simplerealtytheme Advanced Text Widget Plugin < 2.0.1 - XSS
Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79
Jan 24, 2013
CVE-2011-5252
1 PoC
Analysis
NUCLEI
EPSS 0.17
Orchard - Improper Input Validation
Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.
CWE-20
Jan 12, 2013
CVE-2011-4640
1 PoC
Analysis
NUCLEI
EPSS 0.14
Spamtitan Webtitan < 3.50 - Path Traversal
Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.
CWE-22
Oct 08, 2012
CVE-2011-5181
1 PoC
Analysis
NUCLEI
EPSS 0.02
Clickdesk Live Support-live Chat Plugin - XSS
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
CWE-79
Sep 20, 2012
CVE-2011-5179
1 PoC
Analysis
NUCLEI
EPSS 0.02
Skysa App Bar Integration Plugin < 1.03 - XSS
Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
CWE-79
Sep 20, 2012
CVE-2011-4926
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.07
Bueltge Adminimize < 1.7.21 - XSS
Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79
Aug 29, 2012
CVE-2011-5107
1 PoC
Analysis
NUCLEI
EPSS 0.01
Wordpress Alert Before You Post < 0.1.1 - XSS
Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter.
CWE-79
Aug 23, 2012
CVE-2011-5106
1 PoC
Analysis
NUCLEI
EPSS 0.01
Fractalia Flexible Custom Post Type - XSS
Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CWE-79
Aug 23, 2012
CVE-2011-4804
1 PoC
Analysis
NUCLEI
EPSS 0.10
Foobla Com Obsuggest < 1.6.4 - Path Traversal
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
CWE-22
Dec 14, 2011
CVE-2011-3315
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.57
Cisco Unified IP Interactive Voice Response - Path Traversal
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
CWE-22
Oct 27, 2011
CVE-2011-2780
1 PoC
Analysis
NUCLEI
EPSS 0.04
Chyrp < 2.0 - Path Traversal
Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.
CWE-22
Jul 19, 2011
CVE-2011-2744
1 PoC
Analysis
NUCLEI
EPSS 0.02
Chyrp < 2.1 - Path Traversal
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.
CWE-22
Jul 19, 2011
CVE-2011-1669
1 PoC
Analysis
NUCLEI
EPSS 0.01
WP Custom Pages <0.5.0.1 - Path Traversal
Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.
CWE-22
Apr 10, 2011
CVE-2011-0049
1 PoC
Analysis
NUCLEI
EPSS 0.91
Majordomo <20110131 - Path Traversal
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.
CWE-22
Feb 04, 2011
CVE-2011-0518
2 PoCs
Analysis
NUCLEI
EPSS 0.69
Lotuscms Fraise - Path Traversal
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via the system parameter to index.php.
CWE-22
Jan 20, 2011
CVE-2010-20103
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.85
ProFTPD <1.3.3c - RCE
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
CWE-912
Aug 20, 2025
CVE-2010-3867
NUCLEI
EPSS 0.00
Proftpd - Path Traversal
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command.
CWE-22
Nov 09, 2010