Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2024-57049
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.35
TP-Link Archer c20 <V6.6_230412 - Auth Bypass
A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables."
CWE-287
Feb 18, 2025
CVE-2024-57046
8.8
HIGH
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.51
Netgear DGN2200 <v1.0.0.46 - Auth Bypass
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
CWE-287
Feb 18, 2025
CVE-2024-57045
9.8
CRITICAL
1 PoC
1 Writeup
Analysis
NUCLEI
EPSS 0.63
D-Link DIR-859 <A3 1.05 - Auth Bypass
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
CWE-287
Feb 18, 2025
CVE-2024-13609
5.9
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.18
1clickmigration 1 Click Migration < 2.1 - Information Disclosure
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.
CWE-200
Feb 18, 2025
CVE-2024-13726
8.6
HIGH
NUCLEI
EPSS 0.10
Themescoder Themes Coder < 1.3.4 - SQL Injection
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CWE-89
Feb 17, 2025
CVE-2024-13627
4.7
MEDIUM
NUCLEI
EPSS 0.02
Wp-buy Owl Carousel Slider < 2.2 - XSS
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 17, 2025
CVE-2024-13625
7.1
HIGH
NUCLEI
EPSS 0.03
Gualdoni Tube Video Ads Lite < 1.5.7 - XSS
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 17, 2025
CVE-2024-13570
6.1
MEDIUM
NUCLEI
EPSS 0.02
Unalignedcode Stray Random Quotes < 1.9.9 - XSS
The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 11, 2025
CVE-2024-13543
6.1
MEDIUM
NUCLEI
EPSS 0.02
Amini7 Zarinpal Paid Download < 2.3 - XSS
The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 11, 2025
CVE-2024-13492
6.1
MEDIUM
NUCLEI
EPSS 0.02
Guten Free Options <0.9.5 - XSS
The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 07, 2025
CVE-2024-13352
7.1
HIGH
NUCLEI
EPSS 0.03
Legull WordPress <1.2.2 - XSS
The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 07, 2025
CVE-2024-13331
6.1
MEDIUM
NUCLEI
EPSS 0.02
WP Dream Carousel <1.0.1b - XSS
The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13330
7.1
HIGH
NUCLEI
EPSS 0.02
JustRows <0.2 - XSS
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13328
6.1
MEDIUM
NUCLEI
EPSS 0.02
Giga Messenger <2.3.1 - XSS
The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13327
6.1
MEDIUM
NUCLEI
EPSS 0.02
Musicbox WP <2.0.3 - XSS
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13326
6.1
MEDIUM
NUCLEI
EPSS 0.02
iBuildApp WordPress <0.2.0 - XSS
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13325
6.1
MEDIUM
NUCLEI
EPSS 0.02
Glossy WP <2.3.5 - XSS
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Feb 04, 2025
CVE-2024-13114
6.1
MEDIUM
NUCLEI
EPSS 0.02
WP Projects Portfolio - XSS
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 04, 2025
CVE-2024-13099
5.4
MEDIUM
NUCLEI
EPSS 0.04
Widget4Call <1.0.7 - XSS
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 01, 2025
CVE-2024-13098
5.4
MEDIUM
NUCLEI
EPSS 0.03
WordPress Email Newsletter <1.1 - XSS
The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Feb 01, 2025