Vulnerabilities with Nuclei Scanner Templates
Updated 11m agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2022-2733
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.92
Open-emr Openemr < 7.0.0.1 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
CWE-79
Aug 09, 2022
CVE-2022-35493
6.1
MEDIUM
1 Writeup
NUCLEI
EPSS 0.02
Wrteam Eshop - Ecommerce / Store Website < 3.0.4 - XSS
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
CWE-79
Aug 08, 2022
CVE-2022-31656
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.80
Vmware Identity Manager - Authentication Bypass
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Aug 05, 2022
CVE-2022-31181
9.8
CRITICAL
EXPLOITED
1 PoC
Analysis
NUCLEI
EPSS 0.78
PrestaShop <1.7.8.7 - SQL Injection
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.
CWE-74
Aug 01, 2022
CVE-2022-2414
7.5
HIGH
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.91
Dogtagpki - XXE
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
CWE-611
Jul 29, 2022
CVE-2022-34121
7.5
HIGH
EXPLOITED
NUCLEI
EPSS 0.18
Cuppa CMS v1.0 - Local File Inclusion
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
CWE-829
Jul 27, 2022
CVE-2022-36883
7.5
HIGH
3 PoCs
Analysis
NUCLEI
EPSS 0.79
Jenkins Git < 4.11.3 - Missing Authorization
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
CWE-862
Jul 27, 2022
CVE-2022-34576
7.5
HIGH
1 Writeup
NUCLEI
EPSS 0.30
WAVLINK WN535 G3 M35G3R.V5030.180927 - RCE
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Jul 25, 2022
CVE-2022-35653
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.81
Moodle LTI - XSS
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
CWE-79
Jul 25, 2022
CVE-2022-33965
9.3
CRITICAL
NUCLEI
EPSS 0.43
Osamaesh WP Visitor Statistics <5.7 - SQL Injection
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
CWE-89
Jul 25, 2022
CVE-2022-36446
9.8
CRITICAL
5 PoCs
Analysis
NUCLEI
EPSS 0.93
Webmin <1.997 - XSS
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CWE-116
Jul 25, 2022
CVE-2022-33901
5.3
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.10
MultiSafepay <4.13.1 - Info Disclosure
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
CWE-552
Jul 22, 2022
CVE-2022-29495
5.4
MEDIUM
NUCLEI
EPSS 0.02
Sygnoos Popup Builder < 4.1.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
CWE-352
Jul 22, 2022
CVE-2022-34487
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.50
Oxilab Shortcode Addons < 3.0.3 - Access Control
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
CWE-264
Jul 21, 2022
CVE-2022-33198
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.37
Accordions <2.0.2 - Info Disclosure
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
CWE-264
Jul 21, 2022
CVE-2022-28666
5.3
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.13
YIKES Inc. Custom Product Tabs for WooCommerce <=1.7.7 - Info Discl...
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
CWE-287
Jul 21, 2022
CVE-2022-32430
7.5
HIGH
NUCLEI
EPSS 0.78
Lin CMS Spring Boot <0.2.1 - Info Disclosure
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
Jul 21, 2022
CVE-2022-34590
7.2
HIGH
1 Writeup
NUCLEI
EPSS 0.04
Hospital Management System - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
CWE-89
Jul 20, 2022
CVE-2022-26138
9.8
CRITICAL
KEV
SSVC ACTIVE
RANSOMWARE
4 PoCs
Analysis
NUCLEI
EPSS 0.94
Atlassian Questions For Confluence - Hardcoded Credentials
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
CWE-798
Jul 20, 2022
CVE-2022-34049
5.3
MEDIUM
NUCLEI
EPSS 0.16
Wavlink WN530HG4 M30HG4.V5030.191116 - Info Disclosure
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
CWE-552
Jul 20, 2022