Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2024-10914
8.1
HIGH
EXPLOITED
17 PoCs
Analysis
NUCLEI
EPSS 0.94
Dlink Dns-320 Firmware - Command Injection
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CWE-78
Nov 06, 2024
CVE-2024-1183
6.5
MEDIUM
1 Writeup
NUCLEI
EPSS 0.55
Gradio < 4.11.0 - Open Redirect
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.
CWE-601
Apr 16, 2024
CVE-2024-0881
5.4
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.13
WordPress Plugin <2.2.76 - Info Disclosure
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts
Apr 11, 2024
CVE-2024-0337
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.01
Travelpayouts < 1.1.17 - Open Redirect
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
CWE-601
Mar 20, 2024
CVE-2024-0801
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.55
Arcserve Unified Data Protection <9.2,8.1 - DoS
A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
CWE-75
Mar 13, 2024
CVE-2024-0799
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.38
Arcserve Unified Data Protection <9.2,8.1 - Auth Bypass
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
CWE-287
Mar 13, 2024
CVE-2024-1071
9.8
CRITICAL
EXPLOITED
9 PoCs
Analysis
NUCLEI
EPSS 0.93
WordPress Ultimate Member SQL Injection (CVE-2024-1071)
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Mar 13, 2024
CVE-2024-0692
8.8
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.78
SolarWinds Security Event Manager - RCE
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
CWE-502
Mar 01, 2024
CVE-2024-1212
10.0
CRITICAL
KEV
7 PoCs
Analysis
NUCLEI
EPSS 0.94
Progress Loadmaster < 7.2.48.10 - OS Command Injection
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CWE-78
Feb 21, 2024
CVE-2024-0593
5.3
MEDIUM
NUCLEI
EPSS 0.07
Simple Job Board <2.10.8 - Info Disclosure
The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.
CWE-862
Feb 21, 2024
CVE-2024-0250
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.21
Deconf Analytics Insights < 6.3 - Open Redirect
The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
CWE-601
Feb 12, 2024
CVE-2024-1210
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.24
LearnDash LMS <4.10.1 - Info Disclosure
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.
CWE-200
Feb 05, 2024
CVE-2024-1209
5.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.47
LearnDash LMS <4.10.1 - Info Disclosure
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
CWE-200
Feb 05, 2024
CVE-2024-1208
5.3
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.86
LearnDash LMS <4.10.2 - Info Disclosure
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
CWE-200
Feb 05, 2024
CVE-2024-1061
8.6
HIGH
EXPLOITED
NUCLEI
EPSS 0.83
Bplugins Html5 Video Player < 2.5.25 - SQL Injection
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
CWE-89
Jan 30, 2024
CVE-2024-1021
6.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.93
Ruifang-tech Rebuild < 3.5.5 - SSRF
A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the component HTTP Request Handler. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252290 is the identifier assigned to this vulnerability.
CWE-918
Jan 29, 2024
CVE-2024-0986
4.7
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.81
Issabel PBX 4.0.0 - Command Injection
A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-78
Jan 29, 2024
CVE-2024-0939
6.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.88
Byzoro Smart S210 Management Platform <20240117 - Unrestricted Upload
A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-434
Jan 26, 2024
CVE-2024-0204
9.8
CRITICAL
EXPLOITED
9 PoCs
Analysis
NUCLEI
EPSS 0.93
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
CWE-425
Jan 22, 2024
CVE-2024-0705
9.8
CRITICAL
NUCLEI
EPSS 0.20
Stripe Payment Plugin <3.7.9 - SQL Injection
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CWE-89
Jan 19, 2024