Vulnerabilities with Nuclei Scanner Templates

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,589 CVEs tracked 53,640 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,361 vendors 43,897 researchers
4,077 results Clear all
CVE-2022-4295 6.1 MEDIUM NUCLEI EPSS 0.14
Appjetty Show All Comments < 7.0.1 - XSS
The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
Jan 16, 2023
CVE-2022-4060 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.89
User Post Gallery WP <2.19 - Code Injection
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
Jan 16, 2023
CVE-2022-38467 6.1 MEDIUM NUCLEI EPSS 0.18
WordPress Form Builder <1.1.0 - XSS
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
CWE-79 Jan 14, 2023
CVE-2022-4325 6.1 MEDIUM NUCLEI EPSS 0.11
Post Status Notifier Lite <1.10.1 - XSS
The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.
Jan 09, 2023
CVE-2022-4301 6.1 MEDIUM NUCLEI EPSS 0.04
Sunshine Photo Cart <2.9.15 - XSS
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Jan 09, 2023
CVE-2022-44877 9.8 CRITICAL KEV 13 PoCs Analysis NUCLEI EPSS 0.94
CWP login.php Unauthenticated RCE
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
CWE-78 Jan 05, 2023
CVE-2022-38627 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.72
Nortek Linear eMerge E3-Series <0.32-09 - SQL Injection
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
CWE-89 Jan 03, 2023
CVE-2022-4260 4.8 MEDIUM NUCLEI EPSS 0.01
Wp-ban < 1.69.1 - XSS
The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Jan 02, 2023
CVE-2022-4140 7.5 HIGH NUCLEI EPSS 0.56
Welcart e-Commerce <2.8.5 - Info Disclosure
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
Jan 02, 2023
CVE-2022-4059 9.8 CRITICAL NUCLEI EPSS 0.71
Cryptocurrency Widgets Pack <2.0 - SQL Injection
The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CWE-89 Jan 02, 2023
CVE-2022-4057 5.3 MEDIUM NUCLEI EPSS 0.45
Autoptimize <3.1.0 - Info Disclosure
The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.
CWE-425 Jan 02, 2023
CVE-2022-4049 9.8 CRITICAL NUCLEI EPSS 0.78
WP User <7.0 - SQL Injection
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Jan 02, 2023
CVE-2022-48197 6.1 MEDIUM 2 PoCs Analysis NUCLEI EPSS 0.37
Yui < 2800 - XSS
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CWE-79 Jan 02, 2023
CVE-2022-23544 7.2 HIGH 1 Writeup NUCLEI EPSS 0.24
Metersphere < 2.5.0 - SSRF
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.
CWE-918 Dec 28, 2022
CVE-2022-4117 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.84
Iws-geo-form-fields < 1.0 - SQL Injection
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.
Dec 26, 2022
CVE-2022-47945 9.8 CRITICAL EXPLOITED 1 Writeup NUCLEI EPSS 0.90
Thinkphp < 6.0.14 - Path Traversal
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.
CWE-22 Dec 23, 2022
CVE-2022-23854 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.92
AVEVA InTouch Access Anywhere <2020 R2 - Path Traversal
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
CWE-22 Dec 23, 2022
CVE-2022-3805 8.6 HIGH EXPLOITED NUCLEI EPSS 0.08
Jeg Elementor Kit <2.5.6 - Auth Bypass
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.
CWE-639 Dec 22, 2022
CVE-2022-41697 5.3 MEDIUM NUCLEI EPSS 0.13
Ghost Foundation Ghost <5.9.4 - Info Disclosure
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.
CWE-204 Dec 22, 2022
CVE-2022-46020 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.86
WBCE CMS v1.5.4 - Code Injection
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CWE-434 Dec 20, 2022