Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,391 CVEs tracked 53,627 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,294 vendors 43,856 researchers
4,077 results Clear all
CVE-2024-57049 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.35
TP-Link Archer c20 <V6.6_230412 - Auth Bypass
A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables."
CWE-287 Feb 18, 2025
CVE-2024-57046 8.8 HIGH EXPLOITED 1 Writeup NUCLEI EPSS 0.51
Netgear DGN2200 <v1.0.0.46 - Auth Bypass
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
CWE-287 Feb 18, 2025
CVE-2024-57045 9.8 CRITICAL 1 PoC 1 Writeup Analysis NUCLEI EPSS 0.63
D-Link DIR-859 <A3 1.05 - Auth Bypass
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
CWE-287 Feb 18, 2025
CVE-2024-13609 5.9 MEDIUM EXPLOITED NUCLEI EPSS 0.18
1clickmigration 1 Click Migration < 2.1 - Information Disclosure
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.
CWE-200 Feb 18, 2025
CVE-2024-13726 8.6 HIGH NUCLEI EPSS 0.10
Themescoder Themes Coder < 1.3.4 - SQL Injection
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CWE-89 Feb 17, 2025
CVE-2024-13627 4.7 MEDIUM NUCLEI EPSS 0.02
Wp-buy Owl Carousel Slider < 2.2 - XSS
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 17, 2025
CVE-2024-13625 7.1 HIGH NUCLEI EPSS 0.03
Gualdoni Tube Video Ads Lite < 1.5.7 - XSS
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 17, 2025
CVE-2024-13570 6.1 MEDIUM NUCLEI EPSS 0.02
Unalignedcode Stray Random Quotes < 1.9.9 - XSS
The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 11, 2025
CVE-2024-13543 6.1 MEDIUM NUCLEI EPSS 0.02
Amini7 Zarinpal Paid Download < 2.3 - XSS
The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 11, 2025
CVE-2024-13492 6.1 MEDIUM NUCLEI EPSS 0.02
Guten Free Options <0.9.5 - XSS
The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 07, 2025
CVE-2024-13352 7.1 HIGH NUCLEI EPSS 0.03
Legull WordPress <1.2.2 - XSS
The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 07, 2025
CVE-2024-13331 6.1 MEDIUM NUCLEI EPSS 0.02
WP Dream Carousel <1.0.1b - XSS
The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13330 7.1 HIGH NUCLEI EPSS 0.02
JustRows <0.2 - XSS
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13328 6.1 MEDIUM NUCLEI EPSS 0.02
Giga Messenger <2.3.1 - XSS
The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13327 6.1 MEDIUM NUCLEI EPSS 0.02
Musicbox WP <2.0.3 - XSS
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13326 6.1 MEDIUM NUCLEI EPSS 0.02
iBuildApp WordPress <0.2.0 - XSS
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13325 6.1 MEDIUM NUCLEI EPSS 0.02
Glossy WP <2.3.5 - XSS
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79 Feb 04, 2025
CVE-2024-13114 6.1 MEDIUM NUCLEI EPSS 0.02
WP Projects Portfolio - XSS
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 04, 2025
CVE-2024-13099 5.4 MEDIUM NUCLEI EPSS 0.04
Widget4Call <1.0.7 - XSS
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 01, 2025
CVE-2024-13098 5.4 MEDIUM NUCLEI EPSS 0.03
WordPress Email Newsletter <1.1 - XSS
The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 01, 2025