Vulnerabilities with Nuclei Scanner Templates

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,453 CVEs tracked 53,634 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,330 vendors 43,881 researchers
4,077 results Clear all
CVE-2023-51449 5.6 MEDIUM 1 Writeup NUCLEI EPSS 0.81
Gradio <4.11.0 - Path Traversal
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.
CWE-22 Dec 22, 2023
CVE-2023-32590 9.3 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.19
Subscribe TO Category < 2.7.4 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.
CWE-89 Dec 20, 2023
CVE-2023-6977 7.5 HIGH 1 Writeup NUCLEI EPSS 0.83
MLflow < 2.9.2 - Information Disclosure
This vulnerability enables malicious users to read sensitive files on the server.
CWE-29 Dec 20, 2023
CVE-2023-49489 6.1 MEDIUM NUCLEI EPSS 0.01
Kodcloud Kodexplorer - XSS
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
CWE-79 Dec 19, 2023
CVE-2023-44982 5.3 MEDIUM NUCLEI EPSS 0.13
Meowapps Perfect Images < 6.4.5 - Information Disclosure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.
CWE-200 Dec 19, 2023
CVE-2023-6065 5.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.38
Quttera Web Malware Scanner WP <3.4.2.1 - Info Disclosure
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
Dec 18, 2023
CVE-2023-6909 7.5 HIGH 1 Writeup NUCLEI EPSS 0.86
Lfprojects Mlflow < 2.9.2 - Path Traversal
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CWE-29 Dec 18, 2023
CVE-2023-6895 6.3 MEDIUM EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Hikvision Intercom Broadcast System < 4.1.0 - OS Command Injection
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
CWE-78 Dec 17, 2023
CVE-2023-50720 5.3 MEDIUM 1 Writeup NUCLEI EPSS 0.50
Xwiki < 14.10.5 - Information Disclosure
XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. There are no known workarounds for this vulnerability.
CWE-200 Dec 15, 2023
CVE-2023-50719 7.5 HIGH 1 Writeup NUCLEI EPSS 0.51
Xwiki < 14.10.5 - Information Disclosure
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.
CWE-359 Dec 15, 2023
CVE-2023-50917 9.8 CRITICAL EXPLOITED 3 PoCs Analysis NUCLEI EPSS 0.93
Mjdm Majordomo < 2023-11-15 - Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
CWE-77 Dec 15, 2023
CVE-2023-6553 9.8 CRITICAL EXPLOITED 7 PoCs Analysis NUCLEI EPSS 0.93
WordPress Backup Migration Plugin PHP Filter Chain RCE
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CWE-94 Dec 15, 2023
CVE-2023-6831 8.1 HIGH 1 Writeup NUCLEI EPSS 0.74
Lfprojects Mlflow < 2.9.2 - Path Traversal
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CWE-29 Dec 15, 2023
CVE-2023-48084 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.82
Nagios XI < 5.11.3 - SQL Injection
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
CWE-89 Dec 14, 2023
CVE-2023-41621 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.09
Emlog Pro <2.1.14 - XSS
A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.
CWE-79 Dec 13, 2023
CVE-2023-6380 6.1 MEDIUM NUCLEI EPSS 0.43
Open CMS Mercury - Open Redirect
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.
CWE-601 Dec 13, 2023
CVE-2023-6379 5.4 MEDIUM NUCLEI EPSS 0.19
Alkacon Software Open CMS - Mercury Template <15 - XSS
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
CWE-79 Dec 13, 2023
CVE-2023-46455 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.40
GL.iNET GL-AR300M <4.3.7 - Path Traversal
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
CWE-22 Dec 12, 2023
CVE-2023-49494 6.1 MEDIUM NUCLEI EPSS 0.02
Dedecms - XSS
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
CWE-79 Dec 11, 2023
CVE-2023-6655 7.3 HIGH EXPLOITED NUCLEI EPSS 0.25
Hongjing e-HR 2020 - SQL Injection
A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The manipulation of the argument parentid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247358 is the identifier assigned to this vulnerability.
CWE-89 Dec 10, 2023