Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,649 CVEs tracked 53,649 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,377 vendors 43,908 researchers
4,077 results Clear all
CVE-2022-43170 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.05
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".
CWE-79 Oct 28, 2022
CVE-2022-43169 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.07
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".
CWE-79 Oct 28, 2022
CVE-2022-43167 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.06
Rukovoditel <3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".
CWE-79 Oct 28, 2022
CVE-2022-43166 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.04
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".
CWE-79 Oct 28, 2022
CVE-2022-43165 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.04
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".
CWE-79 Oct 28, 2022
CVE-2022-43164 5.4 MEDIUM SSVC PoC NUCLEI EPSS 0.06
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".
CWE-79 Oct 28, 2022
CVE-2022-31678 9.1 CRITICAL EXPLOITED NUCLEI EPSS 0.86
Vmware Cloud Foundation < 3.11 - XXE
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
CWE-611 Oct 28, 2022
CVE-2022-38870 7.5 HIGH SSVC PoC NUCLEI EPSS 0.52
Free5gc <3.2.1 - Info Disclosure
Free5gc v3.2.1 is vulnerable to Information disclosure.
CWE-306 Oct 25, 2022
CVE-2022-42233 9.8 CRITICAL NUCLEI EPSS 0.84
Tenda 11n Firmware - Authentication Bypass
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
CWE-287 Oct 20, 2022
CVE-2022-43018 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
CWE-79 Oct 19, 2022
CVE-2022-43017 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
CWE-79 Oct 19, 2022
CVE-2022-43016 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
CWE-79 Oct 19, 2022
CVE-2022-43015 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
CWE-79 Oct 19, 2022
CVE-2022-43014 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
CWE-79 Oct 19, 2022
CVE-2022-43185 5.4 MEDIUM NUCLEI EPSS 0.05
Rukovoditel v3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
CWE-79 Oct 19, 2022
CVE-2022-40684 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 33 PoCs Analysis NUCLEI EPSS 0.94
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CWE-287 Oct 18, 2022
CVE-2022-42149 9.8 CRITICAL SSVC PoC 1 Writeup NUCLEI EPSS 0.43
Keking Kkfileview - SSRF
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
CWE-918 Oct 17, 2022
CVE-2022-3506 5.4 MEDIUM SSVC PoC 1 Writeup NUCLEI EPSS 0.01
barrykooij/related-posts-for-wp <2.1.3 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
CWE-79 Oct 14, 2022
CVE-2022-41473 6.1 MEDIUM NUCLEI EPSS 0.19
RPCMS v3.0.2 - XSS
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
CWE-79 Oct 13, 2022
CVE-2022-40047 5.4 MEDIUM NUCLEI EPSS 0.24
Flatpress - XSS
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
CWE-79 Oct 11, 2022