Vulnerabilities with Nuclei Scanner Templates

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,589 CVEs tracked 53,640 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,361 vendors 43,897 researchers
4,077 results Clear all
CVE-2022-48164 7.5 HIGH EXPLOITED 1 Writeup NUCLEI EPSS 0.87
Wavlink WL-WN533A8 M33A8.V5030.190716 - Info Disclosure
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Feb 06, 2023
CVE-2022-48165 7.5 HIGH 1 Writeup NUCLEI EPSS 0.81
Wavlink WL-WN530H4 M30H4.V5030.210121 - Info Disclosure
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Feb 03, 2023
CVE-2022-2546 4.7 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.16
All-in-One WP Migration <7.63 - XSS
The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key
Feb 02, 2023
CVE-2022-46934 6.1 MEDIUM NUCLEI EPSS 0.13
kkFileView v4.1.0 - XSS
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CWE-79 Feb 01, 2023
CVE-2022-47003 9.8 CRITICAL NUCLEI EPSS 0.24
Mura CMS <10.0.580 - Auth Bypass
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
CWE-287 Feb 01, 2023
CVE-2022-47002 9.8 CRITICAL NUCLEI EPSS 0.63
Masa CMS <7.4 - Auth Bypass
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
CWE-863 Feb 01, 2023
CVE-2022-4306 5.4 MEDIUM NUCLEI EPSS 0.03
Panda Pods Repeater Field WP <1.5.4 - XSS
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
Jan 30, 2023
CVE-2022-48012 6.1 MEDIUM NUCLEI EPSS 0.05
Opencats - XSS
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.
CWE-79 Jan 27, 2023
CVE-2022-47615 9.3 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.83
Thimpress Learnpress < 4.2.0 - Unrestricted File Upload
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CWE-434 Jan 26, 2023
CVE-2022-45808 9.9 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.84
Thimpress Learnpress < 4.1.7.3.2 - SQL Injection
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CWE-89 Jan 26, 2023
CVE-2022-31711 5.3 MEDIUM EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.82
Vmware Vrealize Log Insight < 4.8 - Information Disclosure
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
CWE-200 Jan 26, 2023
CVE-2022-31706 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Path Traversal
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CWE-22 Jan 26, 2023
CVE-2022-31704 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.90
Vmware Vrealize Log Insight < 4.8 - Improper Access Control
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
CWE-284 Jan 26, 2023
CVE-2022-4305 9.8 CRITICAL NUCLEI EPSS 0.83
WordPress Plugin <3.3 - Privilege Escalation
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
Jan 23, 2023
CVE-2022-41441 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.07
ReQlogic v11.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
CWE-79 Jan 20, 2023
CVE-2022-46888 6.1 MEDIUM NUCLEI EPSS 0.16
NexusPHP <1.7.33 - XSS
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.
CWE-79 Jan 19, 2023
CVE-2022-47966 9.8 CRITICAL KEV RANSOMWARE 8 PoCs Analysis NUCLEI EPSS 0.94
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
CWE-20 Jan 18, 2023
CVE-2022-39195 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.10
Lsoft Listserv - XSS
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
CWE-79 Jan 17, 2023
CVE-2022-4447 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.78
Fontsy < 1.8.6 - SQL Injection
The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Jan 16, 2023
CVE-2022-4320 6.1 MEDIUM NUCLEI EPSS 0.15
WordPress Events Calendar <1.4.5 - XSS
The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).
Jan 16, 2023