Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2005-4385
1 PoC
Analysis
NUCLEI
EPSS 0.00
Cofax 2.0 RC3- - XSS
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.
Dec 20, 2005
CVE-2005-3634
1 PoC
Analysis
NUCLEI
EPSS 0.02
SAP WAS 6.10-7.00 - SSRF
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Nov 16, 2005
CVE-2005-3344
NUCLEI
EPSS 0.10
Horde 3.0.4 - Info Disclosure
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
Nov 16, 2005
CVE-2005-3128
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.02
Address Add Plugin <2.0 - XSS
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
Oct 04, 2005
CVE-2005-2428
3 PoCs
Analysis
NUCLEI
EPSS 0.09
Lotus Domino R5-R6 WebMail - Info Disclosure
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.
Aug 03, 2005
CVE-2004-2687
7 PoCs
Analysis
NUCLEI
EPSS 0.90
distcc 2.x - RCE
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
CWE-16
Dec 31, 2004
CVE-2004-1602
1 PoC
Analysis
NUCLEI
EPSS 0.01
Proftpd < 1.2.10 - Information Disclosure
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
CWE-203
Oct 15, 2004
CVE-2004-1641
1 PoC
Analysis
NUCLEI
EPSS 0.01
South River Technologies Titan FTP Server - Buffer Overflow
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.
Aug 29, 2004
CVE-2004-0656
NUCLEI
EPSS 0.00
PureFTPd <1.0.18 - DoS
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
Aug 06, 2004
CVE-2004-0437
1 PoC
Analysis
NUCLEI
EPSS 0.01
Titan FTP Server <3.01.169 - DoS
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.
Jul 07, 2004
CVE-2004-0519
1 PoC
Analysis
NUCLEI
EPSS 0.00
SquirrelMail 1.4.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
Aug 18, 2004
CVE-2004-1965
5 PoCs
Analysis
NUCLEI
EPSS 0.00
OpenBB 1.0.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.
Apr 25, 2004
CVE-2002-1131
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.03
SquirrelMail <1.2.7 - XSS
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
Oct 04, 2002
CVE-2001-1473
1 PoC
NUCLEI
EPSS 0.05
SSH-1 - Man-in-the-middle
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.
CWE-310
Jan 18, 2001
CVE-2001-0537
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.94
Cisco Ios - Authentication Bypass
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
CWE-287
Jul 21, 2001
CVE-2000-0760
1 PoC
Analysis
NUCLEI
EPSS 0.42
Jakarta Tomcat <3.1-3.0 - Info Disclosure
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
Oct 20, 2000
CVE-2000-0114
3 PoCs
Analysis
NUCLEI
EPSS 0.05
Frontpage Server Extensions - Info Disclosure
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
Feb 02, 2000