Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,077 results Clear all
CVE-2024-57241 6.5 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.23
Dedecms - Open Redirect
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.
CWE-601 Feb 11, 2025
CVE-2024-43144 9.3 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.23
StylemixThemes Cost Calculator <3.2.15 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.
CWE-89 Aug 29, 2024
CVE-2024-30464 5.4 MEDIUM NUCLEI EPSS 0.44
Wpzoom Social Icons Widget < 4.2.16 - Missing Authorization
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
CWE-862 Jun 09, 2024
CVE-2024-12025 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.77
Collapsing Categories <3.0.8 - SQL Injection
The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89 Dec 18, 2024
CVE-2024-30502 9.3 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.18
Wptravelengine WP Travel Engine < 5.8.0 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
CWE-89 Mar 29, 2024
CVE-2024-30498 9.3 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.17
Crmperks Crm Perks Forms < 1.1.5 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.
CWE-89 Mar 29, 2024
CVE-2024-9765 6.5 MEDIUM NUCLEI EPSS 0.05
EKC Tournament Manager <2.2.2 - Path Traversal
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
May 15, 2025
CVE-2024-37261 7.1 HIGH EXPLOITED NUCLEI EPSS 0.14
Wplab Wp-lister Lite For Amazon < 2.6.17 - XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <= 2.6.16.
CWE-79 Jul 22, 2024
CVE-2024-43965 8.2 HIGH 1 PoC Analysis NUCLEI EPSS 0.18
Smackcoders Sendgrid < 1.4 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.
CWE-89 Aug 29, 2024
CVE-2024-8625 7.2 HIGH NUCLEI EPSS 0.03
TS Poll <2.4.0 - SQL Injection
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CWE-89 Oct 21, 2024
CVE-2024-9617 6.5 MEDIUM NUCLEI EPSS 0.16
danswer-ai/danswer v0.3.94 - Info Disclosure
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
CWE-639 Mar 20, 2025
CVE-2024-9643 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.29
Four-faith F3x36 Firmware - Authentication Bypass
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.
CWE-489 Feb 04, 2025
CVE-2024-48651 7.5 HIGH 1 Writeup NUCLEI EPSS 0.37
ProFTPD < 1.3.8b - Privilege Escalation via mod_sql
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
CWE-863 Nov 29, 2024
CVE-2024-9474 7.2 HIGH KEV RANSOMWARE 10 PoCs Analysis NUCLEI EPSS 0.94
Paloaltonetworks Pan-os < 10.1.14 - OS Command Injection
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CWE-78 Nov 18, 2024
CVE-2024-9935 7.5 HIGH 5 PoCs Analysis NUCLEI EPSS 0.94
PDF Generator Addon - Path Traversal
The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-24569 may be a duplicate of this issue.
CWE-22 Nov 16, 2024
CVE-2024-9989 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.93
WordPress Crypto <2.15 - Auth Bypass
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.
CWE-288 Oct 29, 2024
CVE-2024-9772 7.3 HIGH NUCLEI EPSS 0.09
Uiux Uix Shortcodes < 1.9.9 - Code Injection
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CWE-94 Oct 26, 2024
CVE-2024-48208 8.6 HIGH 1 PoC Analysis NUCLEI EPSS 0.39
Pure-FTPd < 1.0.52 - Buffer Overflow
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
CWE-125 Oct 24, 2024
CVE-2024-9593 8.3 HIGH EXPLOITED 4 PoCs Analysis NUCLEI EPSS 0.86
Wpplugin Time Clock < 1.1.4 - Code Injection
The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.
CWE-94 Oct 18, 2024
CVE-2024-9916 7.3 HIGH EXPLOITED 1 Writeup NUCLEI EPSS 0.84
Usualtoolcms - OS Command Injection
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-78 Oct 13, 2024