Vulnerabilities with Nuclei Scanner Templates
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2023-4136
7.4
HIGH
NUCLEI
EPSS 0.23
Craftercms < 3.1.27 - XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
CWE-79
Aug 03, 2023
CVE-2023-4116
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.21
Phpjabbers Taxi Booking Script - XSS
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235963. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4115
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.17
Phpjabbers Cleaning Business Software - XSS
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. VDB-235962 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4114
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.05
Phpjabbers Night Club Booking Software - XSS
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4113
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.14
Phpjabbers Service Booking Script - XSS
A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4112
4.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.14
Phpjabbers Shuttle Booking Software - XSS
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235959. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4111
4.3
MEDIUM
NUCLEI
EPSS 0.15
Phpjabbers Bus Reservation System - XSS
A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-4110
3.5
LOW
NUCLEI
EPSS 0.05
Phpjabbers Availability Booking Calendar - XSS
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CWE-79
Aug 03, 2023
CVE-2023-37679
9.8
CRITICAL
EXPLOITED
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Mirth Connect Deserialization RCE
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
CWE-77
Aug 03, 2023
CVE-2023-39110
8.8
HIGH
1 Writeup
NUCLEI
EPSS 0.80
rconfig v3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918
Aug 01, 2023
CVE-2023-39109
8.8
HIGH
1 Writeup
NUCLEI
EPSS 0.78
rconfig <3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918
Aug 01, 2023
CVE-2023-39108
8.8
HIGH
1 Writeup
NUCLEI
EPSS 0.78
rconfig <3.9.4 - SSRF
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CWE-918
Aug 01, 2023
CVE-2023-34960
9.8
CRITICAL
EXPLOITED
12 PoCs
Analysis
NUCLEI
EPSS 0.94
Chamilo unauthenticated command injection in PowerPoint upload
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
CWE-77
Aug 01, 2023
CVE-2023-37580
6.1
MEDIUM
KEV
NUCLEI
EPSS 0.94
Synacor Zimbra Collaboration Suite < 8.8.15 - XSS
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CWE-79
Jul 31, 2023
CVE-2023-3345
6.5
MEDIUM
NUCLEI
EPSS 0.65
Masteriyo WordPress <1.6.8 - Info Disclosure
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Jul 31, 2023
CVE-2023-38992
9.8
CRITICAL
NUCLEI
EPSS 0.64
jeecg-boot <3.5.1 - SQL Injection
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
CWE-89
Jul 28, 2023
CVE-2023-3990
3.5
LOW
1 PoC
NUCLEI
EPSS 0.09
Mingsoft Mcms < 5.3.1 - XSS
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-235611.
CWE-79
Jul 28, 2023
CVE-2023-37979
7.1
HIGH
5 PoCs
Analysis
NUCLEI
EPSS 0.24
Ninjaforms Ninja Forms < 3.6.26 - XSS
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
CWE-79
Jul 27, 2023
CVE-2023-31465
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.91
FSMLabs TimeKeeper <8.0.28 - Command Injection
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.
Jul 26, 2023
CVE-2023-38433
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.53
Fujitsu Real-time Video Transmission Gear - RCE
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.
CWE-798
Jul 26, 2023