Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2023-37582
9.8
CRITICAL
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache RocketMQ - Remote Command Execution
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
CWE-94
Jul 12, 2023
CVE-2023-33246
9.8
CRITICAL
KEV
16 PoCs
Analysis
NUCLEI
EPSS 0.94
Apache RocketMQ update config RCE
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
CWE-94
May 24, 2023
CVE-2023-22629
8.8
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.65
Southrivertech Titan FTP Server < 1.94.1205 - Path Traversal
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.
CWE-22
Feb 14, 2023
CVE-2023-21839
7.5
HIGH
KEV
8 PoCs
Analysis
NUCLEI
EPSS 0.94
Oracle WebLogic Server <14.1.1.0.0 - RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CWE-502
Jan 18, 2023
CVE-2023-6786
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.01
Hkdigit Payment Gateway For Telcell < 2.0.4 - Open Redirect
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
CWE-601
May 15, 2025
CVE-2023-52163
8.8
HIGH
KEV
NUCLEI
EPSS 0.72
Digiever Ds-2105 Pro Firmware - Missing Authorization
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CWE-862
Feb 03, 2025
CVE-2023-34990
9.8
CRITICAL
NUCLEI
EPSS 0.66
Fortinet Fortiwlm < 8.5.5 - Code Injection
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
CWE-94
Dec 18, 2024
CVE-2023-32117
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.88
SoftLab Integrate Google Drive - Info Disclosure
Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.1.99.
CWE-862
Dec 09, 2024
CVE-2023-27584
9.8
CRITICAL
NUCLEI
EPSS 0.66
Linuxfoundation Dragonfly < 2.0.9 - Authentication Bypass
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CWE-321
Sep 19, 2024
CVE-2023-47105
8.6
HIGH
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.27
Chaosblade < 1.7.4 - OS Command Injection
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
CWE-78
Sep 18, 2024
CVE-2023-45038
4.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.09
Qnap Music Station < 5.4.0 - Authentication Bypass
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following version:
Music Station 5.4.0 and later
CWE-287
Sep 06, 2024
CVE-2023-41954
8.6
HIGH
EXPLOITED
NUCLEI
EPSS 0.17
Properfraction Profilepress < 4.13.2 - Improper Privilege Management
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
CWE-269
May 17, 2024
CVE-2023-37999
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.57
Hasthemes HT Mega < 2.2.1 - Improper Privilege Management
Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.
CWE-269
May 17, 2024
CVE-2023-40504
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.91
LG Simple Editor Command Injection (CVE-2023-40504)
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the readVideoInfo method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
. Was ZDI-CAN-19953.
CWE-78
May 03, 2024
CVE-2023-40000
8.3
HIGH
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.82
Litespeedtech Litespeed Cache < 5.7.0.1 - XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
CWE-79
Apr 16, 2024
CVE-2023-51409
10.0
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.93
Meowapps AI Engine < 1.9.99 - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.
CWE-434
Apr 12, 2024
CVE-2023-7164
7.5
HIGH
NUCLEI
EPSS 0.25
BackWPup <4.0.4 - Path Traversal
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Apr 08, 2024
CVE-2023-34020
4.7
MEDIUM
NUCLEI
EPSS 0.05
Uncanny Owl Uncanny Toolkit for LearnDash <3.6.4.3 - Open Redirect
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.
CWE-601
Mar 27, 2024
CVE-2023-48777
9.9
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.91
Elementor Website Builder <3.18.1 - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.
CWE-434
Mar 26, 2024
CVE-2023-47873
9.1
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.13
Wensolutions WP Child Theme Generator - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
CWE-434
Mar 26, 2024