Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
4,077 results Clear all
CVE-2010-1217 1 PoC Analysis NUCLEI EPSS 0.02
JE Form Creator - Path Traversal
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.
CWE-22 Mar 30, 2010
CVE-2010-1081 1 PoC Analysis NUCLEI EPSS 0.05
Joomla! <1.5.2 - Path Traversal
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 23, 2010
CVE-2010-1056 1 PoC Analysis NUCLEI EPSS 0.04
Joomla! <1.0.1 - Path Traversal
Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 23, 2010
CVE-2010-0985 1 PoC Analysis NUCLEI EPSS 0.05
Joomla! com_abbrev 1.1 - Path Traversal
Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
CWE-22 Mar 16, 2010
CVE-2010-0982 1 PoC Analysis NUCLEI EPSS 0.04
CARTwebERP <1.56.75 - Path Traversal
Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 16, 2010
CVE-2010-0972 1 PoC Analysis NUCLEI EPSS 0.04
Joomla! com_gcalendar 2.1.5 - Path Traversal
Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 16, 2010
CVE-2010-0944 1 PoC Analysis NUCLEI EPSS 0.01
Joomla! - Path Traversal
Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 08, 2010
CVE-2010-0943 1 PoC Analysis NUCLEI EPSS 0.03
Joomla! - Path Traversal
Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.
CWE-22 Mar 08, 2010
CVE-2010-0942 1 PoC Analysis NUCLEI EPSS 0.03
Joomla! - Path Traversal
Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 08, 2010
CVE-2010-0759 EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.06
Core Design Scriptegrator <1.4.1 - Path Traversal
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter, a different vector than CVE-2010-0760.
CWE-22 Feb 27, 2010
CVE-2010-0696 1 PoC Analysis NUCLEI EPSS 0.16
JoomlaWorks AllVideos <3.2 - Path Traversal
Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.
CWE-22 Feb 23, 2010
CVE-2010-0467 5.8 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.03
Chillcreations Com Ccnewsletter - Path Traversal
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
CWE-22 Feb 02, 2010
CVE-2010-0157 1 PoC Analysis NUCLEI EPSS 0.06
Joomlabiblestudy Com Biblestudy - Path Traversal
Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php.
CWE-22 Jan 06, 2010
CVE-2009-0884 NUCLEI EPSS 0.00
Filezilla-project Filezilla Server < 0.9.31 - Buffer Overflow
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.
CWE-120 Mar 12, 2009
CVE-2009-5114 1 PoC Analysis NUCLEI EPSS 0.06
Iwork Webglimpse < 2.18.7 - Path Traversal
Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.
CWE-22 Mar 19, 2012
CVE-2009-5020 NUCLEI EPSS 0.01
Awstats < 6.9 - Improper Input Validation
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CWE-20 Dec 02, 2010
CVE-2009-4679 2 PoCs Analysis NUCLEI EPSS 0.06
Joomla! com_if_nexus 1.5 - Path Traversal
Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
CWE-22 Mar 08, 2010
CVE-2009-4223 1 PoC Analysis NUCLEI EPSS 0.04
KR-Web <1.1b2 - RCE
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
CWE-94 Dec 07, 2009
CVE-2009-4202 1 PoC Analysis NUCLEI EPSS 0.05
Omilen Photo Gallery <Beta 0.5 - Path Traversal
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.
CWE-22 Dec 04, 2009
CVE-2009-3318 1 PoC Analysis NUCLEI EPSS 0.02
Breedveld Com Album - Path Traversal
Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.
CWE-22 Sep 23, 2009