Vulnerabilities with Nuclei Scanner Templates
Updated 11m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-31269
8.2
HIGH
2 PoCs
Analysis
NUCLEI
EPSS 0.81
Nortek Linear eMerge E3-Series <0.32-09c - Info Disclosure
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
CWE-798
Aug 25, 2022
CVE-2022-36804
8.8
HIGH
KEV
SSVC ACTIVE
20 PoCs
Analysis
NUCLEI
EPSS 0.94
Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
CWE-78
Aug 25, 2022
CVE-2022-37153
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.04
Articatech Artica Proxy - XSS
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
CWE-79
Aug 24, 2022
CVE-2022-38463
6.1
MEDIUM
NUCLEI
EPSS 0.48
ServiceNow <San Diego Patch 4b-Patch 6 - XSS
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
CWE-79
Aug 23, 2022
CVE-2022-32772
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.08
Wwbn Avideo - XSS
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.
CWE-79
Aug 22, 2022
CVE-2022-32771
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.10
Wwbn Avideo - XSS
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.
CWE-79
Aug 22, 2022
CVE-2022-32770
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.14
Wwbn Avideo - XSS
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "toast" parameter which is inserted into the document with insufficient sanitization.
CWE-79
Aug 22, 2022
CVE-2022-2552
5.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.51
Duplicator < 1.4.7.1 - Information Disclosure
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
CWE-862
Aug 22, 2022
CVE-2022-2551
7.5
HIGH
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.60
Duplicator <1.4.7 - Info Disclosure
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.
CWE-425
Aug 22, 2022
CVE-2022-2544
7.5
HIGH
NUCLEI
EPSS 0.34
Ninja Job Board <1.3.3 - Path Traversal
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
CWE-425
Aug 22, 2022
CVE-2022-2383
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.06
Feed Them Social <3.0.1 - XSS
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CWE-79
Aug 22, 2022
CVE-2022-37061
9.8
CRITICAL
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Flir Ax8 Firmware < 1.46.16 - OS Command Injection
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
CWE-78
Aug 18, 2022
CVE-2022-35151
6.1
MEDIUM
NUCLEI
EPSS 0.04
Keking Kkfileview - XSS
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
CWE-79
Aug 17, 2022
CVE-2022-2535
5.3
MEDIUM
NUCLEI
EPSS 0.18
SearchWP Live Ajax Search <1.6.2 - Info Disclosure
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
CWE-639
Aug 15, 2022
CVE-2022-2379
7.5
HIGH
NUCLEI
EPSS 0.37
Easy Student Results <2.2.8 - Info Disclosure
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc
CWE-862
Aug 15, 2022
CVE-2022-37042
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
5 PoCs
Analysis
NUCLEI
EPSS 0.94
Synacor Zimbra Collaboration Suite - Path Traversal
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
CWE-22
Aug 12, 2022
CVE-2022-38130
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.62
com.keysight.tentacle.config.ResourceManager - Path Traversal
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.
CWE-89
Aug 10, 2022
CVE-2022-36923
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.33
Zohocorp Manageengine Firewall Analyzer - Improper Access Control
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
CWE-755
Aug 10, 2022
CVE-2022-32429
9.8
CRITICAL
1 PoC
Analysis
NUCLEI
EPSS 0.80
Megatech Msnswitch Firmware - Authentication Bypass
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
CWE-287
Aug 10, 2022
CVE-2022-2756
6.5
MEDIUM
1 Writeup
NUCLEI
EPSS 0.57
Kavita < 0.5.4.1 - SSRF
Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.
CWE-918
Aug 10, 2022