Vulnerabilities with Nuclei Scanner Templates
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-38296
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.81
Cuppa CMS v1.0 - File Upload
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
CWE-434
Sep 12, 2022
CVE-2022-38295
6.1
MEDIUM
NUCLEI
EPSS 0.34
Cuppa CMS v1.0 - XSS
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.
CWE-79
Sep 12, 2022
CVE-2022-37299
6.5
MEDIUM
EXPLOITED
1 PoC
NUCLEI
EPSS 0.17
Shirne Cms - Path Traversal
An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php
CWE-22
Sep 09, 2022
CVE-2022-27593
10.0
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
NUCLEI
EPSS 0.93
QNAP NAS - Path Traversal
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
CWE-610
Sep 08, 2022
CVE-2022-38131
6.1
MEDIUM
NUCLEI
EPSS 0.02
RStudio Connect <2023.01.0 - Open Redirect
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
CWE-601
Sep 06, 2022
CVE-2022-2633
7.5
HIGH
NUCLEI
EPSS 0.89
All-in-One Video Gallery <2.6.0 - SSRF
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.
CWE-610
Sep 06, 2022
CVE-2022-2462
5.3
MEDIUM
1 Writeup
NUCLEI
EPSS 0.06
Transposh Wordpress Translation < 1.0.8.1 - Information Disclosure
The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the response. This makes it possible for unauthenticated users to exfiltrate usernames of individuals who have translated text.
CWE-200
Sep 06, 2022
CVE-2022-2461
5.3
MEDIUM
EXPLOITED
SSVC PoC
NUCLEI
EPSS 0.18
Transposh Wordpress Translation < 1.0.8.1 - Missing Authorization
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.
CWE-862
Sep 06, 2022
CVE-2022-31814
9.8
CRITICAL
EXPLOITED
SSVC PoC
11 PoCs
Analysis
NUCLEI
EPSS 0.94
Netgate Pfblockerng < 2.1.4_26 - OS Command Injection
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
CWE-78
Sep 05, 2022
CVE-2022-2376
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.10
Directorist WP <7.3.1 - Info Disclosure
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
CWE-862
Sep 05, 2022
CVE-2022-36642
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.71
Telosalliance Omnia Mpx Node Firmware < 1.5.0 - Missing Authorization
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
CWE-862
Sep 02, 2022
CVE-2022-38812
6.5
MEDIUM
NUCLEI
EPSS 0.09
AeroCMS 0.1.1 - SQL Injection
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CWE-89
Aug 31, 2022
CVE-2022-37122
7.5
HIGH
1 PoC
Analysis
NUCLEI
EPSS 0.71
Carel Pcoweb Card Firmware < b.2.1.0 - Path Traversal
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CWE-22
Aug 31, 2022
CVE-2022-36553
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.94
Hytec Inter HWL-2511-SS <v1.05 - Command Injection
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
CWE-77
Aug 29, 2022
CVE-2022-2599
6.1
MEDIUM
NUCLEI
EPSS 0.31
WordPress Anti-Malware Security and Brute-Force Firewall <4.21.83 - Cross-Site Scripting
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting
CWE-79
Aug 29, 2022
CVE-2022-2373
5.3
MEDIUM
NUCLEI
EPSS 0.08
Simply Schedule Appointments WP <1.5.7.7 - Info Disclosure
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
CWE-862
Aug 29, 2022
CVE-2022-38794
7.5
HIGH
NUCLEI
EPSS 0.49
Zaver <2020-12-15 - Path Traversal
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
CWE-22
Aug 27, 2022
CVE-2022-36537
7.5
HIGH
KEV
SSVC ACTIVE
RANSOMWARE
3 PoCs
Analysis
NUCLEI
EPSS 0.94
ZK Framework <9.6.1 - Info Disclosure
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
Aug 26, 2022
CVE-2022-31798
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.87
Nortekcontrol Emerge E3 Firmware < 0.32-07p - XSS
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
CWE-384
Aug 25, 2022
CVE-2022-31499
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.93
Nortek Linear eMerge E3-Series <0.32-08f - Command Injection
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
CWE-78
Aug 25, 2022