Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,482 CVEs tracked 53,635 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,335 vendors 43,883 researchers
4,077 results Clear all
CVE-2023-37474 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.90
9001 Copyparty < 1.8.2 - Path Traversal
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CWE-22 Jul 14, 2023
CVE-2023-37599 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.86
Issabel Pbx - Exposure to Wrong Actor
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
CWE-668 Jul 13, 2023
CVE-2023-34133 7.5 HIGH EXPLOITED NUCLEI EPSS 0.66
Sonicwall
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CWE-89 Jul 13, 2023
CVE-2023-34124 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
SonicWall GMS <9.3.2-SP1 & Analytics <2.5.0.4-R7 - Auth Bypass
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CWE-305 Jul 13, 2023
CVE-2023-37629 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.87
Simple Online Piggery Management System - Unrestricted File Upload
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
CWE-434 Jul 12, 2023
CVE-2023-29300 9.8 CRITICAL KEV RANSOMWARE 1 PoC NUCLEI EPSS 0.94
Adobe ColdFusion <2018u16, <2021u6, <2023.0.0.330468 - Code Injection
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
CWE-502 Jul 12, 2023
CVE-2023-29298 7.5 HIGH KEV NUCLEI EPSS 0.94
Adobe ColdFusion <2018u16, 2021u6, 2023.0.0.330468 - Security Featu...
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
CWE-284 Jul 12, 2023
CVE-2023-3578 5.5 MEDIUM 1 Writeup NUCLEI EPSS 0.81
DedeCMS 5.7.109 - SSRF
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
CWE-918 Jul 10, 2023
CVE-2023-3219 5.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.74
Eventon < 2.1.2 - IDOR
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
CWE-639 Jul 10, 2023
CVE-2023-3077 9.8 CRITICAL NUCLEI EPSS 0.61
MStore API WordPress <3.9.8 - SQL Injection
The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.
Jul 10, 2023
CVE-2023-2796 5.3 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.72
Eventon < 2.1.2 - Missing Authorization
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
CWE-862 Jul 10, 2023
CVE-2023-37270 7.6 HIGH 1 Writeup NUCLEI EPSS 0.59
Piwigo < 13.8.0 - SQL Injection
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix for this issue. As another mitigation, those who want to execute a SQL statement verbatim with user-enterable parameters should be sure to escape the parameter contents appropriately.
CWE-89 Jul 07, 2023
CVE-2023-34192 9.0 CRITICAL KEV NUCLEI EPSS 0.89
Zimbra ZCS <8.8.15 - XSS
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
CWE-79 Jul 06, 2023
CVE-2023-3521 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.19
fossbilling/fossbilling <0.5.4 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
CWE-79 Jul 06, 2023
CVE-2023-36934 9.1 CRITICAL EXPLOITED NUCLEI EPSS 0.91
Progress Moveit Transfer < 12.1.11 - SQL Injection
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
CWE-89 Jul 05, 2023
CVE-2023-3460 9.8 CRITICAL EXPLOITED 12 PoCs Analysis NUCLEI EPSS 0.93
Ultimate Member <2.6.7 - Privilege Escalation
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
Jul 04, 2023
CVE-2023-3139 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.08
Protect WP Admin <4.0 - Info Disclosure
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
CWE-601 Jul 04, 2023
CVE-2023-26258 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.79
Arcserve UDP <9.0.6034 - Auth Bypass
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
CWE-863 Jul 03, 2023
CVE-2023-36144 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.85
Intelbras Switch SG 2404 MR - Auth Bypass
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.
CWE-862 Jun 30, 2023
CVE-2023-3479 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.24
Hestiacp Control Panel < 1.7.8 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
CWE-79 Jun 30, 2023