Vulnerabilities with Nuclei Scanner Templates
Updated 6h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-4295
6.1
MEDIUM
NUCLEI
EPSS 0.14
Appjetty Show All Comments < 7.0.1 - XSS
The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
Jan 16, 2023
CVE-2022-4060
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.89
User Post Gallery WP <2.19 - Code Injection
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
Jan 16, 2023
CVE-2022-38467
6.1
MEDIUM
NUCLEI
EPSS 0.18
WordPress Form Builder <1.1.0 - XSS
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
CWE-79
Jan 14, 2023
CVE-2022-4325
6.1
MEDIUM
NUCLEI
EPSS 0.11
Post Status Notifier Lite <1.10.1 - XSS
The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.
Jan 09, 2023
CVE-2022-4301
6.1
MEDIUM
NUCLEI
EPSS 0.04
Sunshine Photo Cart <2.9.15 - XSS
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Jan 09, 2023
CVE-2022-44877
9.8
CRITICAL
KEV
13 PoCs
Analysis
NUCLEI
EPSS 0.94
CWP login.php Unauthenticated RCE
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
CWE-78
Jan 05, 2023
CVE-2022-38627
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.72
Nortek Linear eMerge E3-Series <0.32-09 - SQL Injection
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
CWE-89
Jan 03, 2023
CVE-2022-4260
4.8
MEDIUM
NUCLEI
EPSS 0.01
Wp-ban < 1.69.1 - XSS
The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Jan 02, 2023
CVE-2022-4140
7.5
HIGH
NUCLEI
EPSS 0.56
Welcart e-Commerce <2.8.5 - Info Disclosure
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
Jan 02, 2023
CVE-2022-4059
9.8
CRITICAL
NUCLEI
EPSS 0.71
Cryptocurrency Widgets Pack <2.0 - SQL Injection
The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CWE-89
Jan 02, 2023
CVE-2022-4057
5.3
MEDIUM
NUCLEI
EPSS 0.45
Autoptimize <3.1.0 - Info Disclosure
The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.
CWE-425
Jan 02, 2023
CVE-2022-4049
9.8
CRITICAL
NUCLEI
EPSS 0.78
WP User <7.0 - SQL Injection
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Jan 02, 2023
CVE-2022-48197
6.1
MEDIUM
2 PoCs
Analysis
NUCLEI
EPSS 0.37
Yui < 2800 - XSS
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CWE-79
Jan 02, 2023
CVE-2022-23544
7.2
HIGH
1 Writeup
NUCLEI
EPSS 0.24
Metersphere < 2.5.0 - SSRF
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.
CWE-918
Dec 28, 2022
CVE-2022-4117
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.84
Iws-geo-form-fields < 1.0 - SQL Injection
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.
Dec 26, 2022
CVE-2022-47945
9.8
CRITICAL
EXPLOITED
1 Writeup
NUCLEI
EPSS 0.90
Thinkphp < 6.0.14 - Path Traversal
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.
CWE-22
Dec 23, 2022
CVE-2022-23854
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.92
AVEVA InTouch Access Anywhere <2020 R2 - Path Traversal
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
CWE-22
Dec 23, 2022
CVE-2022-3805
8.6
HIGH
EXPLOITED
NUCLEI
EPSS 0.08
Jeg Elementor Kit <2.5.6 - Auth Bypass
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.
CWE-639
Dec 22, 2022
CVE-2022-41697
5.3
MEDIUM
NUCLEI
EPSS 0.13
Ghost Foundation Ghost <5.9.4 - Info Disclosure
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.
CWE-204
Dec 22, 2022
CVE-2022-46020
9.8
CRITICAL
1 Writeup
NUCLEI
EPSS 0.86
WBCE CMS v1.5.4 - Code Injection
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CWE-434
Dec 20, 2022