Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
4,077 results Clear all
CVE-2009-3053 1 PoC Analysis NUCLEI EPSS 0.02
Jvitals Com Agora - Path Traversal
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.
CWE-22 Sep 03, 2009
CVE-2009-1872 EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.08
Adobe Coldfusion < 8.0.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
CWE-79 Aug 18, 2009
CVE-2009-2100 1 PoC Analysis NUCLEI EPSS 0.02
JoomlaPraise Projectfork <2.0.10 - Path Traversal
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.
CWE-22 Jun 17, 2009
CVE-2009-2015 1 PoC Analysis NUCLEI EPSS 0.02
Joomla! com_moofaq 1.0 - Path Traversal
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CWE-22 Jun 09, 2009
CVE-2009-1558 EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.08
Cisco Wvc54gca - Path Traversal
Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.
CWE-22 May 06, 2009
CVE-2009-1496 1 PoC Analysis NUCLEI EPSS 0.02
Ijobid Com Cmimarketplace - Path Traversal
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.
CWE-22 May 01, 2009
CVE-2009-1151 9.8 CRITICAL KEV 7 PoCs Analysis NUCLEI EPSS 0.93
Phpmyadmin < 2.11.9.5 - Code Injection
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
CWE-94 Mar 26, 2009
CVE-2009-0932 1 PoC Analysis NUCLEI EPSS 0.06
Debian Horde - Path Traversal
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
CWE-22 Mar 17, 2009
CVE-2009-0545 EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.94
ZeroShell <1.0beta11 - Command Injection
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
CWE-20 Feb 12, 2009
CVE-2009-0347 2 PoCs Analysis NUCLEI EPSS 0.04
Autonomy Ultraseek - Open Redirect
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
CWE-59 Jan 29, 2009
CVE-2008-5281 1 PoC Analysis NUCLEI EPSS 0.01
Titan FTP Server 6.05 - Buffer Overflow
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.
CWE-119 Nov 29, 2008
CVE-2008-0702 1 PoC Analysis NUCLEI EPSS 0.03
South River Technologies Titan FTP Server - Memory Corruption
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different vectors than CVE-2004-1641.
CWE-119 Feb 12, 2008
CVE-2008-7269 2 PoCs Analysis NUCLEI EPSS 0.03
SiteEngine 5.x - Open Redirect
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.
CWE-20 Dec 01, 2010
CVE-2008-6982 1 PoC Analysis NUCLEI EPSS 0.09
Devalcms - XSS
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.
CWE-79 Aug 19, 2009
CVE-2008-6668 EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.01
Dirk Bartley Nweb2fax < 0.2.7 - Path Traversal
Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.
CWE-22 Apr 08, 2009
CVE-2008-6465 NUCLEI EPSS 0.01
Parallels H-sphere - XSS
Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.
CWE-79 Mar 13, 2009
CVE-2008-6222 2 PoCs Analysis NUCLEI EPSS 0.02
Joomlashowroom Pro Desk Support Center - Path Traversal
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.
CWE-22 Feb 20, 2009
CVE-2008-6172 1 PoC Analysis NUCLEI EPSS 0.05
Weberr Rwcards - Path Traversal
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.
CWE-22 Feb 19, 2009
CVE-2008-6080 1 PoC Analysis NUCLEI EPSS 0.07
ionFiles 4.4.2 - Path Traversal
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CWE-22 Feb 06, 2009
CVE-2008-5587 1 PoC Analysis NUCLEI EPSS 0.02
phpPgAdmin <4.2.1 - Path Traversal
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
CWE-22 Dec 16, 2008