Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,077 results Clear all
CVE-2023-39650 9.8 CRITICAL NUCLEI EPSS 0.29
Themevolty Theme Volty Cms Blog < 4.0.1 - SQL Injection
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
CWE-89 Aug 28, 2023
CVE-2023-41109 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.92
SmartNode SN200 3.21.2-23021 - Command Injection
SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
CWE-78 Aug 28, 2023
CVE-2023-39560 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.61
Ectouch - SQL Injection
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
CWE-89 Aug 28, 2023
CVE-2023-40755 6.1 MEDIUM NUCLEI EPSS 0.02
PHPJabbers Callback Widget v1.0 - XSS
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.
CWE-79 Aug 28, 2023
CVE-2023-40753 5.4 MEDIUM NUCLEI EPSS 0.01
PHPJabbers Ticket Support Script <3.2 - XSS
There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.
CWE-79 Aug 28, 2023
CVE-2023-40752 6.1 MEDIUM NUCLEI EPSS 0.01
PHPJabbers Make an Offer Widget v1.0 - XSS
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.
CWE-79 Aug 28, 2023
CVE-2023-40751 6.1 MEDIUM NUCLEI EPSS 0.01
PHPJabbers Fundraising Script v1.0 - XSS
PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.
CWE-79 Aug 28, 2023
CVE-2023-40750 6.1 MEDIUM NUCLEI EPSS 0.01
PHPJabbers Yacht Listing Script <1.0 - XSS
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.
CWE-79 Aug 28, 2023
CVE-2023-40749 9.8 CRITICAL NUCLEI EPSS 0.44
PHPJabbers Food Delivery Script v3.0 - SQL Injection
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
CWE-89 Aug 28, 2023
CVE-2023-40748 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.44
PHPJabbers Food Delivery Script 3.0 - SQL Injection
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
CWE-89 Aug 28, 2023
CVE-2023-4547 3.5 LOW 1 PoC Analysis NUCLEI EPSS 0.10
SPA-Cart eCommerce CMS 1.9.0.3 - XSS
A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.
CWE-79 Aug 26, 2023
CVE-2023-4542 6.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.92
D-Link DAR-8000-10 <20230809 - Code Injection
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-78 Aug 25, 2023
CVE-2023-39600 6.1 MEDIUM NUCLEI EPSS 0.04
Icewarp - XSS
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
CWE-79 Aug 25, 2023
CVE-2023-39700 6.1 MEDIUM NUCLEI EPSS 0.14
Icewarp Mail Server - XSS
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
CWE-79 Aug 25, 2023
CVE-2023-32077 7.5 HIGH 1 Writeup NUCLEI EPSS 0.87
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.
CWE-321 Aug 24, 2023
CVE-2023-39026 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.81
FileMage Gateway <1.10.8 - Path Traversal
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
CWE-22 Aug 22, 2023
CVE-2023-39141 7.5 HIGH 2 PoCs Analysis NUCLEI EPSS 0.86
webui-aria2 <4fe2 - Path Traversal
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
CWE-22 Aug 22, 2023
CVE-2023-3936 6.1 MEDIUM NUCLEI EPSS 0.16
Adenion Blog2social < 7.2.1 - XSS
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Aug 21, 2023
CVE-2023-38035 9.8 CRITICAL KEV RANSOMWARE 5 PoCs Analysis NUCLEI EPSS 0.94
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
CWE-863 Aug 21, 2023
CVE-2023-4450 6.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Jeecg Jimureport < 1.6.1 - Injection
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.
CWE-74 Aug 21, 2023