Vulnerabilities with Nuclei Scanner Templates

Updated 54m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,402 CVEs tracked 53,629 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,301 vendors 43,863 researchers
4,077 results Clear all
CVE-2024-13097 5.4 MEDIUM NUCLEI EPSS 0.03
WP Finance <1.3.6 - XSS
The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Feb 01, 2025
CVE-2024-52875 8.8 HIGH EXPLOITED NUCLEI EPSS 0.79
GFI Kerio Control < 9.4.5 - XSS
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.
CWE-113 Jan 31, 2025
CVE-2024-13226 6.1 MEDIUM NUCLEI EPSS 0.02
A5 Custom Login Page <2.8.1 - XSS
The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13225 6.1 MEDIUM NUCLEI EPSS 0.01
ECT Home Page Products <1.9 - XSS
The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13224 6.1 MEDIUM NUCLEI EPSS 0.01
SlideDeck 1 Lite Content Slider WP <1.4.8 - XSS
The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13222 6.1 MEDIUM NUCLEI EPSS 0.02
User Messages <1.2.4 - XSS
The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13221 6.1 MEDIUM NUCLEI EPSS 0.02
Fantastic ElasticSearch WP <4.1.0 - XSS
The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13220 6.1 MEDIUM NUCLEI EPSS 0.02
WordPress Google Map Professional <1.0 - XSS
The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13219 6.1 MEDIUM NUCLEI EPSS 0.02
Privacy Policy Genius WP <2.0.4 - XSS
The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-13112 6.1 MEDIUM NUCLEI EPSS 0.02
WP MediaTagger <4.1.1 - XSS
The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79 Jan 31, 2025
CVE-2024-55417 4.3 MEDIUM 1 Writeup NUCLEI EPSS 0.23
Thecontrolgroup Voyager < 1.8.0 - Unrestricted File Upload
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
CWE-434 Jan 30, 2025
CVE-2024-55416 3.5 LOW 1 Writeup NUCLEI EPSS 0.02
Thecontrolgroup Voyager < 1.8.0 - XSS
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
CWE-79 Jan 30, 2025
CVE-2024-55415 5.7 MEDIUM 1 Writeup NUCLEI EPSS 0.60
Thecontrolgroup Voyager < 1.8.0 - Path Traversal
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
CWE-22 Jan 30, 2025
CVE-2024-57514 4.8 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.08
TP-Link Archer A20 v3 - XSS
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.
CWE-79 Jan 28, 2025
CVE-2024-13496 7.5 HIGH NUCLEI EPSS 0.20
GamiPress - Time-Based SQL Injection
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was previously published as being fixed in version 7.2.2 which was incorrect. The correct fixed version is 7.3.2.
CWE-89 Jan 22, 2025
CVE-2024-50967 6.5 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.38
Becon DATAGerry <2.2.0 - Info Disclosure
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.
CWE-862 Jan 17, 2025
CVE-2024-57727 7.5 HIGH KEV RANSOMWARE 3 PoCs Analysis NUCLEI EPSS 0.94
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
CWE-22 Jan 15, 2025
CVE-2024-50857 4.8 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.00
Gestioip - XSS
The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.
CWE-79 Jan 14, 2025
CVE-2024-13161 9.8 CRITICAL KEV NUCLEI EPSS 0.92
Ivanti EPM - Path Traversal
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CWE-36 Jan 14, 2025
CVE-2024-13160 9.8 CRITICAL KEV NUCLEI EPSS 0.93
Ivanti EPM - Path Traversal
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CWE-36 Jan 14, 2025