Vulnerabilities with Nuclei Scanner Templates

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,682 CVEs tracked 53,700 with exploits 4,860 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,389 vendors 43,933 researchers
4,077 results Clear all
CVE-2022-26833 9.4 CRITICAL EXPLOITED NUCLEI EPSS 0.92
Open Automation Software OAS Platform 16.00.0121 - Auth Bypass
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.
CWE-306 May 25, 2022
CVE-2022-29349 6.1 MEDIUM NUCLEI EPSS 0.02
kkFileView v4.0.0 - XSS
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CWE-79 May 25, 2022
CVE-2022-29005 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.07
Online Birth Certificate System v1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
CWE-79 May 23, 2022
CVE-2022-29004 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.40
Diary Management System v1.0 - XSS
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
CWE-79 May 23, 2022
CVE-2022-31268 7.5 HIGH 1 Writeup NUCLEI EPSS 0.90
Gitblit 1.9.3 - Path Traversal
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
CWE-22 May 21, 2022
CVE-2022-28987 5.3 MEDIUM EXPLOITED 1 Writeup NUCLEI EPSS 0.11
Zoho ManageEngine ADSelfService Plus <6.2.02 - Info Disclosure
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
May 20, 2022
CVE-2022-28955 7.5 HIGH 1 Writeup NUCLEI EPSS 0.93
D-Link DIR816L_FW206b01 - Info Disclosure
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
CWE-287 May 18, 2022
CVE-2022-30073 5.4 MEDIUM NUCLEI EPSS 0.18
Wbce Cms - XSS
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
CWE-79 May 17, 2022
CVE-2022-24856 9.1 CRITICAL 1 Writeup NUCLEI EPSS 0.82
Flyte Console < 0.52.0 - SSRF
FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a workaround.
CWE-918 May 17, 2022
CVE-2022-30777 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.04
Parallels H-Sphere <3.6.1713 - XSS
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
CWE-79 May 16, 2022
CVE-2022-30776 6.1 MEDIUM NUCLEI EPSS 0.46
atmail 6.5.0 - XSS
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
CWE-79 May 16, 2022
CVE-2022-30489 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.29
Wavlink Wn535g3 Firmware - XSS
WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.
CWE-79 May 13, 2022
CVE-2022-29383 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.75
NETGEAR ProSafe SSL VPN - SQL Injection
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
CWE-89 May 13, 2022
CVE-2022-29303 9.8 CRITICAL KEV SSVC ACTIVE 3 PoCs Analysis NUCLEI EPSS 0.94
SolarView Compact 6.00 - Command Injection
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CWE-78 May 12, 2022
CVE-2022-29298 7.5 HIGH 1 PoC Analysis NUCLEI EPSS 0.81
SolarView Compact <6.00 - Path Traversal
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
CWE-22 May 12, 2022
CVE-2022-30525 9.8 CRITICAL KEV SSVC ACTIVE RANSOMWARE 17 PoCs Analysis NUCLEI EPSS 0.94
Zyxel Firewall SUID Binary Privilege Escalation
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CWE-78 May 12, 2022
CVE-2022-29009 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.75
Cyber Cafe Management System Project v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29007 9.8 CRITICAL EXPLOITED 2 PoCs Analysis NUCLEI EPSS 0.93
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29006 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.87
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022
CVE-2022-29316 9.8 CRITICAL NUCLEI EPSS 0.60
Complete Online Job Search System v1.0 - SQL Injection
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.
CWE-89 May 11, 2022