Vulnerabilities with Nuclei Scanner Templates
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-43170
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.05
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".
CWE-79
Oct 28, 2022
CVE-2022-43169
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.07
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".
CWE-79
Oct 28, 2022
CVE-2022-43167
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.06
Rukovoditel <3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".
CWE-79
Oct 28, 2022
CVE-2022-43166
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.04
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".
CWE-79
Oct 28, 2022
CVE-2022-43165
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.04
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".
CWE-79
Oct 28, 2022
CVE-2022-43164
5.4
MEDIUM
SSVC PoC
NUCLEI
EPSS 0.06
Rukovoditel 3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".
CWE-79
Oct 28, 2022
CVE-2022-31678
9.1
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.86
Vmware Cloud Foundation < 3.11 - XXE
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
CWE-611
Oct 28, 2022
CVE-2022-38870
7.5
HIGH
SSVC PoC
NUCLEI
EPSS 0.52
Free5gc <3.2.1 - Info Disclosure
Free5gc v3.2.1 is vulnerable to Information disclosure.
CWE-306
Oct 25, 2022
CVE-2022-42233
9.8
CRITICAL
NUCLEI
EPSS 0.84
Tenda 11n Firmware - Authentication Bypass
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
CWE-287
Oct 20, 2022
CVE-2022-43018
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
CWE-79
Oct 19, 2022
CVE-2022-43017
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
CWE-79
Oct 19, 2022
CVE-2022-43016
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
CWE-79
Oct 19, 2022
CVE-2022-43015
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
CWE-79
Oct 19, 2022
CVE-2022-43014
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Opencats - XSS
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
CWE-79
Oct 19, 2022
CVE-2022-43185
5.4
MEDIUM
NUCLEI
EPSS 0.05
Rukovoditel v3.2.1 - XSS
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
CWE-79
Oct 19, 2022
CVE-2022-40684
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
33 PoCs
Analysis
NUCLEI
EPSS 0.94
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CWE-287
Oct 18, 2022
CVE-2022-42149
9.8
CRITICAL
SSVC PoC
1 Writeup
NUCLEI
EPSS 0.43
Keking Kkfileview - SSRF
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
CWE-918
Oct 17, 2022
CVE-2022-3506
5.4
MEDIUM
SSVC PoC
1 Writeup
NUCLEI
EPSS 0.01
barrykooij/related-posts-for-wp <2.1.3 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
CWE-79
Oct 14, 2022
CVE-2022-41473
6.1
MEDIUM
NUCLEI
EPSS 0.19
RPCMS v3.0.2 - XSS
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
CWE-79
Oct 13, 2022
CVE-2022-40047
5.4
MEDIUM
NUCLEI
EPSS 0.24
Flatpress - XSS
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
CWE-79
Oct 11, 2022