Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-38840
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.58
Güralp MAN-EAM-0003 3.2.4 - XXE
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.
CWE-611
Apr 16, 2023
CVE-2022-47501
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.86
Apache Ofbiz < 18.12.07 - Path Traversal
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
This issue affects Apache OFBiz: before 18.12.07.
CWE-22
Apr 14, 2023
CVE-2022-39048
6.1
MEDIUM
NUCLEI
EPSS 0.15
ServiceNow - XSS
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.
CWE-79
Apr 10, 2023
CVE-2022-4940
7.3
HIGH
EXPLOITED
NUCLEI
EPSS 0.14
WCFM Membership <2.10.0 - Info Disclosure
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.
CWE-862
Apr 05, 2023
CVE-2022-43939
8.6
HIGH
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.93
Hitachi Vantara Pentaho <9.4.0.1-9.3.0.2 - SSRF
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
CWE-647
Apr 03, 2023
CVE-2022-43769
8.8
HIGH
KEV
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
CWE-74
Apr 03, 2023
CVE-2022-31474
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.92
iThemes BackupBuddy <8.7.4.1 - Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.
CWE-22
Mar 13, 2023
CVE-2022-4328
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.80
WooCommerce Checkout Field Manager <18.0 - Code Injection
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
Mar 06, 2023
CVE-2022-47075
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.92
Smart Office Web <20.28 - Info Disclosure
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
Feb 28, 2023
CVE-2022-4897
6.1
MEDIUM
NUCLEI
EPSS 0.22
BackupBuddy <8.8.3 - XSS
The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Feb 21, 2023
CVE-2022-47986
9.8
CRITICAL
KEV
RANSOMWARE
6 PoCs
Analysis
NUCLEI
EPSS 0.94
IBM Aspera Faspex < 4.4.1 - Insecure Deserialization
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
CWE-502
Feb 17, 2023
CVE-2022-40032
9.8
CRITICAL
2 PoCs
Analysis
NUCLEI
EPSS 0.68
Simple Task Managing System - SQL Injection
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
CWE-89
Feb 17, 2023
CVE-2022-39952
9.8
CRITICAL
EXPLOITED
6 PoCs
Analysis
NUCLEI
EPSS 0.94
Fortinet FortiNAC keyUpload.jsp arbitrary file write
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
CWE-668
Feb 16, 2023
CVE-2022-40022
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.91
Symmetricom SyncServer Unauthenticated Remote Command Execution
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CWE-77
Feb 13, 2023
CVE-2022-48323
9.8
CRITICAL
EXPLOITED
1 PoC
1 Writeup
Analysis
NUCLEI
EPSS 0.87
Sunlogin Sunflower - Path Traversal
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.
CWE-22
Feb 13, 2023
CVE-2022-45699
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.90
Apsystems Ecu-r Firmware - Code Injection
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
CWE-78
Feb 10, 2023
CVE-2022-24990
7.5
HIGH
KEV
RANSOMWARE
7 PoCs
Analysis
NUCLEI
EPSS 0.94
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
CWE-306
Feb 07, 2023
CVE-2022-28923
6.1
MEDIUM
NUCLEI
EPSS 0.03
Caddy v2.4.6 - Open Redirect
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
CWE-601
Feb 06, 2023
CVE-2022-48166
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.66
Wavlink Wl-wn530hg4 Firmware - Missing Authorization
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
CWE-862
Feb 06, 2023
CVE-2022-4321
6.1
MEDIUM
NUCLEI
EPSS 0.10
PDF Generator for WordPress <1.1.2 - XSS
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Feb 06, 2023