Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,544 CVEs tracked 53,640 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,344 vendors 43,890 researchers
4,077 results Clear all
CVE-2023-28121 9.8 CRITICAL EXPLOITED 9 PoCs Analysis NUCLEI EPSS 0.94
Automattic Woocommerce Payments < 4.8.2 - Authentication Bypass
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
CWE-287 Apr 12, 2023
CVE-2023-27032 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.40
Prestashop advancedpopupcreator <1.1.24 - SQL Injection
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().
CWE-89 Apr 12, 2023
CVE-2023-27179 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.82
GDidees CMS <3.9.1 - Info Disclosure
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
CWE-434 Apr 11, 2023
CVE-2023-26067 8.1 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Lexmark <2023-02-19 - Info Disclosure
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
CWE-20 Apr 10, 2023
CVE-2023-27163 6.5 MEDIUM EXPLOITED 30 PoCs Analysis NUCLEI EPSS 0.93
request-baskets <1.2.1 - SSRF
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
CWE-918 Mar 31, 2023
CVE-2023-27159 7.5 HIGH EXPLOITED NUCLEI EPSS 0.80
Appwrite <1.2.1 - SSRF
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
CWE-918 Mar 31, 2023
CVE-2023-27008 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.40
ATutor 2.2.1 - XSS
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
CWE-79 Mar 28, 2023
CVE-2023-27847 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.69
Xipblog < 2.0.1 - SQL Injection
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.
CWE-89 Mar 27, 2023
CVE-2023-26802 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.84
DCN DCBI-Netlog-LAB v1.0 - Command Injection
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.
CWE-22 Mar 26, 2023
CVE-2023-27034 9.8 CRITICAL EXPLOITED 1 PoC NUCLEI EPSS 0.90
PrestaShop jmsblog 2.5.5 - SQL Injection
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
CWE-89 Mar 23, 2023
CVE-2023-26360 8.6 HIGH KEV 7 PoCs Analysis NUCLEI EPSS 0.94
Adobe ColdFusion <2018 Update 15, 2021 Update 5 - RCE
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
CWE-284 Mar 23, 2023
CVE-2023-28665 5.4 MEDIUM NUCLEI EPSS 0.22
Woo Bulk Price Update <2.2.2 - XSS
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
CWE-79 Mar 22, 2023
CVE-2023-28662 9.8 CRITICAL NUCLEI EPSS 0.74
The Gift Cards <4.3.1 - SQL Injection
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.
CWE-89 Mar 22, 2023
CVE-2023-28432 7.5 HIGH KEV 20 PoCs Analysis NUCLEI EPSS 0.94
Minio <RELEASE.2023-03-20T20-16-18Z - Info Disclosure
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
CWE-200 Mar 22, 2023
CVE-2023-27638 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.39
Tshirtecommerce Custom Product Designer - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CWE-89 Mar 22, 2023
CVE-2023-27637 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.39
Tshirtecommerce Custom Product Designer - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CWE-89 Mar 22, 2023
CVE-2023-25280 9.8 CRITICAL KEV NUCLEI EPSS 0.93
Dlink Dir-820l Firmware - OS Command Injection
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
CWE-78 Mar 16, 2023
CVE-2023-28343 9.8 CRITICAL EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.94
Apsystems Energy Communication Unit Firmware - OS Command Injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
CWE-78 Mar 14, 2023
CVE-2023-27587 7.4 HIGH EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.87
Readtomyshoe < 2023-03-13 - Error Information Exposure
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates from the Google Cloud TTS request, then it will include the full URL of the request. The request URL contains the Google Cloud API key. This has been patched in commit 8533b01. Upgrading should be accompanied by deleting the current GCP API key and issuing a new one. There are no known workarounds.
CWE-209 Mar 13, 2023
CVE-2023-25573 8.6 HIGH EXPLOITED NUCLEI EPSS 0.94
Metersphere < 1.20.19 - Missing Authorization
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CWE-862 Mar 09, 2023