Vulnerabilities with Nuclei Scanner Templates

Updated 11m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-2733 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.92
Open-emr Openemr < 7.0.0.1 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
CWE-79 Aug 09, 2022
CVE-2022-35493 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
Wrteam Eshop - Ecommerce / Store Website < 3.0.4 - XSS
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
CWE-79 Aug 08, 2022
CVE-2022-31656 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.80
Vmware Identity Manager - Authentication Bypass
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Aug 05, 2022
CVE-2022-31181 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.78
PrestaShop <1.7.8.7 - SQL Injection
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.
CWE-74 Aug 01, 2022
CVE-2022-2414 7.5 HIGH EXPLOITED 5 PoCs Analysis NUCLEI EPSS 0.91
Dogtagpki - XXE
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
CWE-611 Jul 29, 2022
CVE-2022-34121 7.5 HIGH EXPLOITED NUCLEI EPSS 0.18
Cuppa CMS v1.0 - Local File Inclusion
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
CWE-829 Jul 27, 2022
CVE-2022-36883 7.5 HIGH 3 PoCs Analysis NUCLEI EPSS 0.79
Jenkins Git < 4.11.3 - Missing Authorization
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
CWE-862 Jul 27, 2022
CVE-2022-34576 7.5 HIGH 1 Writeup NUCLEI EPSS 0.30
WAVLINK WN535 G3 M35G3R.V5030.180927 - RCE
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Jul 25, 2022
CVE-2022-35653 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.81
Moodle LTI - XSS
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
CWE-79 Jul 25, 2022
CVE-2022-33965 9.3 CRITICAL NUCLEI EPSS 0.43
Osamaesh WP Visitor Statistics <5.7 - SQL Injection
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
CWE-89 Jul 25, 2022
CVE-2022-36446 9.8 CRITICAL 5 PoCs Analysis NUCLEI EPSS 0.93
Webmin <1.997 - XSS
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CWE-116 Jul 25, 2022
CVE-2022-33901 5.3 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.10
MultiSafepay <4.13.1 - Info Disclosure
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
CWE-552 Jul 22, 2022
CVE-2022-29495 5.4 MEDIUM NUCLEI EPSS 0.02
Sygnoos Popup Builder < 4.1.12 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
CWE-352 Jul 22, 2022
CVE-2022-34487 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.50
Oxilab Shortcode Addons < 3.0.3 - Access Control
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
CWE-264 Jul 21, 2022
CVE-2022-33198 9.8 CRITICAL EXPLOITED NUCLEI EPSS 0.37
Accordions <2.0.2 - Info Disclosure
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
CWE-264 Jul 21, 2022
CVE-2022-28666 5.3 MEDIUM EXPLOITED NUCLEI EPSS 0.13
YIKES Inc. Custom Product Tabs for WooCommerce <=1.7.7 - Info Discl...
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
CWE-287 Jul 21, 2022
CVE-2022-32430 7.5 HIGH NUCLEI EPSS 0.78
Lin CMS Spring Boot <0.2.1 - Info Disclosure
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
Jul 21, 2022
CVE-2022-34590 7.2 HIGH 1 Writeup NUCLEI EPSS 0.04
Hospital Management System - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
CWE-89 Jul 20, 2022
CVE-2022-26138 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 4 PoCs Analysis NUCLEI EPSS 0.94
Atlassian Questions For Confluence - Hardcoded Credentials
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
CWE-798 Jul 20, 2022
CVE-2022-34049 5.3 MEDIUM NUCLEI EPSS 0.16
Wavlink WN530HG4 M30HG4.V5030.191116 - Info Disclosure
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
CWE-552 Jul 20, 2022