Vulnerabilities with Nuclei Scanner Templates
Updated 11m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2024-7354
6.1
MEDIUM
NUCLEI
EPSS 0.01
Ninjaforms Ninja Forms < 3.8.11 - XSS
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CWE-79
Sep 02, 2024
CVE-2024-6586
7.3
HIGH
NUCLEI
EPSS 0.22
Lightdash 0.1024.6 - SSRF
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST request to /api/v1/dashboards//export. The forged request contains the value of the exporting user’s session token. A threat actor could obtain the session token of any user who exports the dashboard. The obtained session token can be used to perform actions as the victim on the application, resulting in session takeover.
CWE-201
Aug 30, 2024
CVE-2024-3673
9.1
CRITICAL
3 PoCs
Analysis
NUCLEI
EPSS 0.92
Web Directory Free <1.7.3 - Code Injection
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
Aug 30, 2024
CVE-2024-45488
9.8
CRITICAL
NUCLEI
EPSS 0.86
One Identity Safeguard for Privileged Passwords <7.5.2 - Info Discl...
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.
Aug 30, 2024
CVE-2024-6671
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.73
WhatsUp Gold <2024.0.0 - SQL Injection
In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
CWE-89
Aug 29, 2024
CVE-2024-6670
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
WhatsUp Gold SQL Injection (CVE-2024-6670)
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
CWE-89
Aug 29, 2024
CVE-2024-43917
9.3
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.90
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.
CWE-89
Aug 29, 2024
CVE-2024-5057
9.3
CRITICAL
EXPLOITED
1 PoC
NUCLEI
EPSS 0.64
Awesomemotive Easy Digital Downloads < 3.2.12 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
CWE-89
Aug 29, 2024
CVE-2024-45440
5.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.87
Drupal 11.x-dev - Info Disclosure
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
CWE-209
Aug 29, 2024
CVE-2024-8181
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.61
Flowise <1.8.2 - Auth Bypass
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
CWE-287
Aug 27, 2024
CVE-2024-43283
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.16
Contest Gallery <23.1.2 - Info Disclosure
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.
CWE-201
Aug 26, 2024
CVE-2024-45241
7.5
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.91
CentralSquare CryWolf - Path Traversal
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
CWE-22
Aug 26, 2024
CVE-2024-7313
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.64
Getshieldsecurity Shield Security < 20.0.6 - XSS
The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CWE-79
Aug 26, 2024
CVE-2024-7954
9.8
CRITICAL
EXPLOITED
12 PoCs
Analysis
NUCLEI
EPSS 0.94
SPIP - RCE
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
CWE-1286
Aug 23, 2024
CVE-2024-42852
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.03
AcuToWeb server <10.5.0.7577C8b - XSS
Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.
CWE-79
Aug 23, 2024
CVE-2024-28987
9.1
CRITICAL
KEV
9 PoCs
Analysis
NUCLEI
EPSS 0.94
SolarWinds Web Help Desk - Hardcoded Credential
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
CWE-798
Aug 21, 2024
CVE-2024-28000
9.8
CRITICAL
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.92
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
CWE-266
Aug 21, 2024
CVE-2024-7854
10.0
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.80
Sjhoo Woo Inquiry - SQL Injection
The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Aug 21, 2024
CVE-2024-5932
10.0
CRITICAL
EXPLOITED
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Givewp < 3.14.2 - Insecure Deserialization
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
CWE-502
Aug 20, 2024
CVE-2024-7928
4.3
MEDIUM
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.92
Fastadmin < 1.3.4.20220530 - Path Traversal
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.
CWE-22
Aug 19, 2024