Vulnerabilities with Nuclei Scanner Templates

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,589 CVEs tracked 53,640 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,361 vendors 43,897 researchers
4,077 results Clear all
CVE-2022-38840 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.58
Güralp MAN-EAM-0003 3.2.4 - XXE
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.
CWE-611 Apr 16, 2023
CVE-2022-47501 7.5 HIGH EXPLOITED NUCLEI EPSS 0.86
Apache Ofbiz < 18.12.07 - Path Traversal
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
CWE-22 Apr 14, 2023
CVE-2022-39048 6.1 MEDIUM NUCLEI EPSS 0.15
ServiceNow - XSS
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.
CWE-79 Apr 10, 2023
CVE-2022-4940 7.3 HIGH EXPLOITED NUCLEI EPSS 0.14
WCFM Membership <2.10.0 - Info Disclosure
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.
CWE-862 Apr 05, 2023
CVE-2022-43939 8.6 HIGH KEV 3 PoCs Analysis NUCLEI EPSS 0.93
Hitachi Vantara Pentaho <9.4.0.1-9.3.0.2 - SSRF
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
CWE-647 Apr 03, 2023
CVE-2022-43769 8.8 HIGH KEV 3 PoCs Analysis NUCLEI EPSS 0.94
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
CWE-74 Apr 03, 2023
CVE-2022-31474 7.5 HIGH EXPLOITED NUCLEI EPSS 0.92
iThemes BackupBuddy <8.7.4.1 - Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.
CWE-22 Mar 13, 2023
CVE-2022-4328 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.80
WooCommerce Checkout Field Manager <18.0 - Code Injection
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
Mar 06, 2023
CVE-2022-47075 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.92
Smart Office Web <20.28 - Info Disclosure
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
Feb 28, 2023
CVE-2022-4897 6.1 MEDIUM NUCLEI EPSS 0.22
BackupBuddy <8.8.3 - XSS
The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Feb 21, 2023
CVE-2022-47986 9.8 CRITICAL KEV RANSOMWARE 6 PoCs Analysis NUCLEI EPSS 0.94
IBM Aspera Faspex < 4.4.1 - Insecure Deserialization
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
CWE-502 Feb 17, 2023
CVE-2022-40032 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.68
Simple Task Managing System - SQL Injection
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
CWE-89 Feb 17, 2023
CVE-2022-39952 9.8 CRITICAL EXPLOITED 6 PoCs Analysis NUCLEI EPSS 0.94
Fortinet FortiNAC keyUpload.jsp arbitrary file write
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
CWE-668 Feb 16, 2023
CVE-2022-40022 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.91
Symmetricom SyncServer Unauthenticated Remote Command Execution
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CWE-77 Feb 13, 2023
CVE-2022-48323 9.8 CRITICAL EXPLOITED 1 PoC 1 Writeup Analysis NUCLEI EPSS 0.87
Sunlogin Sunflower - Path Traversal
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.
CWE-22 Feb 13, 2023
CVE-2022-45699 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.90
Apsystems Ecu-r Firmware - Code Injection
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
CWE-78 Feb 10, 2023
CVE-2022-24990 7.5 HIGH KEV RANSOMWARE 7 PoCs Analysis NUCLEI EPSS 0.94
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
CWE-306 Feb 07, 2023
CVE-2022-28923 6.1 MEDIUM NUCLEI EPSS 0.03
Caddy v2.4.6 - Open Redirect
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
CWE-601 Feb 06, 2023
CVE-2022-48166 7.5 HIGH 1 Writeup NUCLEI EPSS 0.66
Wavlink Wl-wn530hg4 Firmware - Missing Authorization
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
CWE-862 Feb 06, 2023
CVE-2022-4321 6.1 MEDIUM NUCLEI EPSS 0.10
PDF Generator for WordPress <1.1.2 - XSS
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Feb 06, 2023