Vulnerabilities with Nuclei Scanner Templates
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-44957
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Webtareas - XSS
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79
Dec 02, 2022
CVE-2022-44952
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".
CWE-79
Dec 02, 2022
CVE-2022-44951
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79
Dec 02, 2022
CVE-2022-44950
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CWE-79
Dec 02, 2022
CVE-2022-44949
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.
CWE-79
Dec 02, 2022
CVE-2022-44948
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.02
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
CWE-79
Dec 02, 2022
CVE-2022-44947
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".
CWE-79
Dec 02, 2022
CVE-2022-44946
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CWE-79
Dec 02, 2022
CVE-2022-44944
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.01
Rukovoditel - XSS
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CWE-79
Dec 02, 2022
CVE-2022-44291
9.8
CRITICAL
SSVC PoC
NUCLEI
EPSS 0.66
webTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CWE-89
Dec 02, 2022
CVE-2022-44290
9.8
CRITICAL
SSVC PoC
NUCLEI
EPSS 0.66
webTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CWE-89
Dec 02, 2022
CVE-2022-41412
8.6
HIGH
EXPLOITED
SSVC PoC
1 PoC
Analysis
NUCLEI
EPSS 0.90
perfSONAR <4.4.5 - SSRF
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
CWE-918
Nov 30, 2022
CVE-2022-44356
7.5
HIGH
SSVC PoC
1 Writeup
NUCLEI
EPSS 0.47
WAVLINK Quantum D4G - Info Disclosure
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
CWE-552
Nov 29, 2022
CVE-2022-3768
8.8
HIGH
SSVC PoC
NUCLEI
EPSS 0.61
Wpsmartcontracts < 1.3.12 - SQL Injection
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
CWE-89
Nov 28, 2022
CVE-2022-45933
9.8
CRITICAL
EXPLOITED
SSVC PoC
NUCLEI
EPSS 0.93
Kubeview < 0.1.31 - Missing Authentication
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."
CWE-306
Nov 27, 2022
CVE-2022-45038
5.4
MEDIUM
NUCLEI
EPSS 0.21
Wbce Cms - XSS
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
CWE-79
Nov 25, 2022
CVE-2022-45037
5.4
MEDIUM
NUCLEI
EPSS 0.21
Wbce Cms - XSS
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.
CWE-79
Nov 25, 2022
CVE-2022-42095
4.8
MEDIUM
SSVC PoC
1 PoC
Analysis
NUCLEI
EPSS 0.42
Backdropcms Backdrop Cms - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CWE-79
Nov 23, 2022
CVE-2022-42094
4.8
MEDIUM
SSVC PoC
1 PoC
Analysis
NUCLEI
EPSS 0.38
Backdrop - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
CWE-79
Nov 22, 2022
CVE-2022-42096
4.8
MEDIUM
SSVC PoC
1 PoC
Analysis
NUCLEI
EPSS 0.21
Backdropcms Backdrop Cms - XSS
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CWE-79
Nov 21, 2022