Vulnerabilities with Nuclei Scanner Templates
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2010-4239
9.8
CRITICAL
NUCLEI
EPSS 0.56
Tikiwiki Cms/groupware - Improper Input Validation
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
CWE-20
Oct 28, 2019
CVE-2010-5286
1 PoC
Analysis
NUCLEI
EPSS 0.32
Joomla! - Path Traversal
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
CWE-22
Nov 26, 2012
CVE-2010-5278
1 PoC
Analysis
NUCLEI
EPSS 0.19
MODx Revolution <2.0.2-pl - Path Traversal
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.
CWE-22
Oct 07, 2012
CVE-2010-5028
2 PoCs
Analysis
NUCLEI
EPSS 0.02
Joomla! com_jejob 1.0 - SQL Injection
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.
CWE-89
Nov 02, 2011
CVE-2010-4977
1 PoC
Analysis
NUCLEI
EPSS 0.00
Joomla! com_canteen 1.0 - SQL Injection
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.
CWE-89
Nov 01, 2011
CVE-2010-4769
1 PoC
Analysis
NUCLEI
EPSS 0.05
Joomla! com_jimtawl 1.0.2 - Path Traversal
Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the task parameter to index.php.
CWE-22
Mar 23, 2011
CVE-2010-4719
1 PoC
Analysis
NUCLEI
EPSS 0.05
JRadio <1.5.1 - Path Traversal
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
CWE-22
Feb 01, 2011
CVE-2010-4617
1 PoC
Analysis
NUCLEI
EPSS 0.01
Kanich Com Jotloader - Path Traversal
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.
CWE-22
Dec 29, 2010
CVE-2010-4282
1 PoC
Analysis
NUCLEI
EPSS 0.05
Artica Pandora Fms < 3.1 - Path Traversal
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
CWE-22
Dec 02, 2010
CVE-2010-4231
2 PoCs
Analysis
NUCLEI
EPSS 0.04
Camtron Cmnc-200 Firmware - Path Traversal
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
CWE-22
Nov 17, 2010
CVE-2010-0219
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.93
Apache Axis2 - Credentials Management
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
CWE-255
Oct 18, 2010
CVE-2010-3426
1 PoC
Analysis
NUCLEI
EPSS 0.01
JPhone <1.0 Alpha 3 - Path Traversal
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
CWE-22
Sep 16, 2010
CVE-2010-3203
1 PoC
Analysis
NUCLEI
EPSS 0.04
PicSell 1.0 - Path Traversal
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.
CWE-22
Sep 03, 2010
CVE-2010-1870
3 PoCs
Analysis
NUCLEI
EPSS 0.93
Struts 2.0.0-2.1.8.1 - RCE
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504.
Aug 17, 2010
CVE-2010-2861
9.8
CRITICAL
KEV
RANSOMWARE
4 PoCs
Analysis
NUCLEI
EPSS 0.94
Adobe ColdFusion <9.0.1 - Path Traversal
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
CWE-22
Aug 11, 2010
CVE-2010-2920
1 PoC
Analysis
NUCLEI
EPSS 0.04
Joomla! com_foobla_suggestions 1.5.1.2 - Path Traversal
Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
CWE-22
Jul 30, 2010
CVE-2010-2918
2 PoCs
Analysis
NUCLEI
EPSS 0.02
Visites 1.1 RC2 - RCE
PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
CWE-94
Jul 30, 2010
CVE-2010-2857
1 PoC
Analysis
NUCLEI
EPSS 0.02
Joomla! - Path Traversal
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.
CWE-22
Jul 25, 2010
CVE-2010-2682
1 PoC
Analysis
NUCLEI
EPSS 0.02
Realtyna Translator 1.0.15 - Path Traversal
Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
CWE-22
Jul 12, 2010
CVE-2010-2680
1 PoC
Analysis
NUCLEI
EPSS 0.02
Joomla! - Path Traversal
Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.
CWE-22
Jul 12, 2010