Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,649 CVEs tracked 53,649 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,377 vendors 43,908 researchers
4,077 results Clear all
CVE-2022-44957 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Webtareas - XSS
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79 Dec 02, 2022
CVE-2022-44952 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".
CWE-79 Dec 02, 2022
CVE-2022-44951 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79 Dec 02, 2022
CVE-2022-44950 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79 Dec 02, 2022
CVE-2022-44949 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.
CWE-79 Dec 02, 2022
CVE-2022-44948 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
CWE-79 Dec 02, 2022
CVE-2022-44947 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".
CWE-79 Dec 02, 2022
CVE-2022-44946 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CWE-79 Dec 02, 2022
CVE-2022-44944 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CWE-79 Dec 02, 2022
CVE-2022-44291 9.8 CRITICAL SSVC PoC NUCLEI EPSS 0.66
webTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CWE-89 Dec 02, 2022
CVE-2022-44290 9.8 CRITICAL SSVC PoC NUCLEI EPSS 0.66
webTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CWE-89 Dec 02, 2022
CVE-2022-41412 8.6 HIGH EXPLOITED SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.90
perfSONAR <4.4.5 - SSRF
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
CWE-918 Nov 30, 2022
CVE-2022-44356 7.5 HIGH SSVC PoC 1 Writeup NUCLEI EPSS 0.47
WAVLINK Quantum D4G - Info Disclosure
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
CWE-552 Nov 29, 2022
CVE-2022-3768 8.8 HIGH SSVC PoC NUCLEI EPSS 0.61
Wpsmartcontracts < 1.3.12 - SQL Injection
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
CWE-89 Nov 28, 2022
CVE-2022-45933 9.8 CRITICAL EXPLOITED SSVC PoC NUCLEI EPSS 0.93
Kubeview < 0.1.31 - Missing Authentication
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."
CWE-306 Nov 27, 2022
CVE-2022-45038 5.4 MEDIUM NUCLEI EPSS 0.21
Wbce Cms - XSS
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
CWE-79 Nov 25, 2022
CVE-2022-45037 5.4 MEDIUM NUCLEI EPSS 0.21
Wbce Cms - XSS
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.
CWE-79 Nov 25, 2022
CVE-2022-42095 4.8 MEDIUM SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.42
Backdropcms Backdrop Cms - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CWE-79 Nov 23, 2022
CVE-2022-42094 4.8 MEDIUM SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.38
Backdrop - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
CWE-79 Nov 22, 2022
CVE-2022-42096 4.8 MEDIUM SSVC PoC 1 PoC Analysis NUCLEI EPSS 0.21
Backdropcms Backdrop Cms - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CWE-79 Nov 21, 2022