Vulnerabilities with Nuclei Scanner Templates

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-31854 7.2 HIGH 2 PoCs Analysis NUCLEI EPSS 0.80
Codologic Codoforum - Unrestricted File Upload
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
CWE-434 Jul 07, 2022
CVE-2022-31126 10.0 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.90
Roxy-wi <6.1.1.0 - RCE
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
CWE-74 Jul 06, 2022
CVE-2022-32094 9.8 CRITICAL NUCLEI EPSS 0.27
Hospital Management System - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
CWE-89 Jul 01, 2022
CVE-2022-29272 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.04
Nagios XI <5.8.5 - Open Redirect
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
CWE-601 Jun 29, 2022
CVE-2022-31101 8.1 HIGH SSVC PoC 3 PoCs Analysis NUCLEI EPSS 0.33
Prestashop <2.1.1 - SQL Injection
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
CWE-89 Jun 27, 2022
CVE-2022-34328 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.04
Sigb Pmb - XSS
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
CWE-79 Jun 23, 2022
CVE-2022-34305 6.1 MEDIUM EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.17
Apache Tomcat < 8.5.81 - XSS
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
CWE-79 Jun 23, 2022
CVE-2022-29775 9.8 CRITICAL 1 Writeup NUCLEI EPSS 0.64
Ispy - Authentication Bypass
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
CWE-287 Jun 21, 2022
CVE-2022-33119 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.02
NUUO NVRsolo <3.06.02 - XSS
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
CWE-79 Jun 21, 2022
CVE-2022-31373 6.1 MEDIUM 1 Writeup NUCLEI EPSS 0.04
SolarView Compact v6.0 - XSS
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
CWE-79 Jun 21, 2022
CVE-2022-32444 6.1 MEDIUM NUCLEI EPSS 0.04
Yuba U5cms - Open Redirect
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
CWE-601 Jun 17, 2022
CVE-2022-31299 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.34
Haraj v3.7 - XSS
Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.
CWE-79 Jun 16, 2022
CVE-2022-31847 7.5 HIGH EXPLOITED 1 Writeup NUCLEI EPSS 0.51
WAVLINK WN579 X3 M79X3.V5030.180719 - Info Disclosure
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.
CWE-425 Jun 14, 2022
CVE-2022-31846 7.5 HIGH 1 Writeup NUCLEI EPSS 0.26
Wavlink Wn535g3 Firmware - Exposure to Wrong Actor
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
CWE-668 Jun 14, 2022
CVE-2022-31845 7.5 HIGH 1 Writeup NUCLEI EPSS 0.53
Wavlink Wn535g3 Firmware - Exposure to Wrong Actor
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
CWE-668 Jun 14, 2022
CVE-2022-33174 9.8 CRITICAL 1 PoC Analysis NUCLEI EPSS 0.72
Powertek firmware <3.30.30 - Auth Bypass
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
CWE-863 Jun 13, 2022
CVE-2022-29455 4.7 MEDIUM 7 PoCs Analysis NUCLEI EPSS 0.56
Elementor Website Builder < 3.5.5 - XSS
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
CWE-79 Jun 13, 2022
CVE-2022-32195 6.1 MEDIUM NUCLEI EPSS 0.04
Open Edx < 2022-06-06 - XSS
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
CWE-79 Jun 09, 2022
CVE-2022-29014 7.5 HIGH EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.66
Razer Sila Gaming Router <2.0.441_api-2.0.418 - Info Disclosure
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.
Jun 09, 2022
CVE-2022-29013 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.93
Razer Sila Gaming Router <v2.0.441_api-2.0.418 - Command Injection
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.
CWE-78 Jun 09, 2022