Vulnerabilities with Nuclei Scanner Templates

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,077 results Clear all
CVE-2023-4136 7.4 HIGH NUCLEI EPSS 0.23
Craftercms < 3.1.27 - XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
CWE-79 Aug 03, 2023
CVE-2023-4116 4.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.21
Phpjabbers Taxi Booking Script - XSS
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235963. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4115 4.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.17
Phpjabbers Cleaning Business Software - XSS
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. VDB-235962 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4114 4.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.05
Phpjabbers Night Club Booking Software - XSS
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4113 4.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.14
Phpjabbers Service Booking Script - XSS
A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4112 4.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.14
Phpjabbers Shuttle Booking Software - XSS
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235959. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4111 4.3 MEDIUM NUCLEI EPSS 0.15
Phpjabbers Bus Reservation System - XSS
A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-4110 3.5 LOW NUCLEI EPSS 0.05
Phpjabbers Availability Booking Calendar - XSS
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79 Aug 03, 2023
CVE-2023-37679 9.8 CRITICAL EXPLOITED RANSOMWARE 2 PoCs Analysis NUCLEI EPSS 0.94
Mirth Connect Deserialization RCE
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
CWE-77 Aug 03, 2023
CVE-2023-39110 8.8 HIGH 1 Writeup NUCLEI EPSS 0.80
rconfig v3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918 Aug 01, 2023
CVE-2023-39109 8.8 HIGH 1 Writeup NUCLEI EPSS 0.78
rconfig <3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918 Aug 01, 2023
CVE-2023-39108 8.8 HIGH 1 Writeup NUCLEI EPSS 0.78
rconfig <3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918 Aug 01, 2023
CVE-2023-34960 9.8 CRITICAL EXPLOITED 12 PoCs Analysis NUCLEI EPSS 0.94
Chamilo unauthenticated command injection in PowerPoint upload
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
CWE-77 Aug 01, 2023
CVE-2023-37580 6.1 MEDIUM KEV NUCLEI EPSS 0.94
Synacor Zimbra Collaboration Suite < 8.8.15 - XSS
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CWE-79 Jul 31, 2023
CVE-2023-3345 6.5 MEDIUM NUCLEI EPSS 0.65
Masteriyo WordPress <1.6.8 - Info Disclosure
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Jul 31, 2023
CVE-2023-38992 9.8 CRITICAL NUCLEI EPSS 0.64
jeecg-boot <3.5.1 - SQL Injection
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
CWE-89 Jul 28, 2023
CVE-2023-3990 3.5 LOW 1 PoC NUCLEI EPSS 0.09
Mingsoft Mcms < 5.3.1 - XSS
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-235611.
CWE-79 Jul 28, 2023
CVE-2023-37979 7.1 HIGH 5 PoCs Analysis NUCLEI EPSS 0.24
Ninjaforms Ninja Forms < 3.6.26 - XSS
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
CWE-79 Jul 27, 2023
CVE-2023-31465 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.91
FSMLabs TimeKeeper <8.0.28 - Command Injection
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.
Jul 26, 2023
CVE-2023-38433 7.5 HIGH EXPLOITED NUCLEI EPSS 0.53
Fujitsu Real-time Video Transmission Gear - RCE
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.
CWE-798 Jul 26, 2023