Nuclei POC 精选分析 - 2025-12-31

Nuclei POC 精选分析 - 2025-12-31

📊 智能筛选概况

  • 发现变更: 627 个模板更新
  • 精选分析: 30 个高价值 POC
  • 智能跳过: 597 个低优先级模板
  • 高风险漏洞: 17 个
  • 主要类别: CVE漏洞(30)

💡 智能筛选说明: 系统自动优先分析 CVE 漏洞、高危漏洞和新增模板,跳过低价值的技术识别类模板,确保高效利用 API 资源。

严重程度分布

  • 🔴 严重: 7 个
  • 🟠 高危: 10 个
  • 🟡 中危: 13 个

🔍 重点漏洞分析

Abandoned Cart Lite for WooCommerce - Authentication Bypass

  • 漏洞ID: CVE-2023-2986
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: WordPress 站点
  • 预估影响: 数千万个

描述: The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, who are typically customers. Further security hardening was introduced in version 5.15.1 that ensures sites are no longer vulnerable through historical check-out links, and additional hardening was introduced in version 5.15.2 that ensured null key values wouldn't permit the authentication bypass.

攻击向量: 网络扫描

CVE编号: CVE-2023-2986

参考链接:


Privileged Remote Access & Remote Support - Command Injection

  • 漏洞ID: CVE-2024-12356
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

攻击向量: 网络扫描

CVE编号: CVE-2024-12356

参考链接:


XZ - Embedded Malicious Code

  • 漏洞ID: CVE-2024-3094
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

攻击向量: 网络扫描

CVE编号: CVE-2024-3094

参考链接:


InvoiceShelf <= 1.3.0 - PHP Deserialization

  • 漏洞ID: CVE-2024-55556
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: InvoiceShelf version 1.3.0 and below contains an unauthenticated PHP deserialization vulnerability that can lead to remote code execution. An attacker with knowledge of the APP_KEY can achieve remote command execution on the server through Laravel's cookie deserialization. While the vulnerability is severe, it is partially mitigated in default installations as the APP_KEY is regenerated during setup.

攻击向量: 网络扫描

CVE编号: CVE-2024-55556

参考链接:


Keras Model.load_model - Arbitrary Code Execution

  • 漏洞ID: CVE-2025-1550
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading

攻击向量: 网络扫描

参考链接:


GitLab - SAML Authentication Bypass

  • 漏洞ID: CVE-2025-25291
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: GitLab 平台
  • 预估影响: 数千个

描述: ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 fix the issue.

攻击向量: 网络扫描

CVE编号: CVE-2025-25291

参考链接:


Horde Groupware Unauthenticated Admin Access

  • 漏洞ID: CVE-2005-3344
  • 严重程度: 🔴 CRITICAL
  • 风险等级: 极高风险 (5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: Horde Groupware contains an administrative account with a blank password, which allows remote attackers to gain access.

攻击向量: 网络扫描

CVE编号: CVE-2005-3344

参考链接:


Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization

  • 漏洞ID: CVE-2021-4448
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: WordPress 站点
  • 预估影响: 数千万个

描述: The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.

攻击向量: 网络扫描

CVE编号: CVE-2021-4448

参考链接:


Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization

  • 漏洞ID: CVE-2021-4448
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: WordPress 站点
  • 预估影响: 数千万个

描述: The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.

攻击向量: 网络扫描

CVE编号: CVE-2021-4448

参考链接:


Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass

  • 漏洞ID: CVE-2020-13125
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: WordPress 站点
  • 预估影响: 数千万个

描述: An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

攻击向量: 网络扫描

CVE编号: CVE-2020-13125

参考链接:


YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting

  • 漏洞ID: CVE-2024-4455
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: WordPress 站点
  • 预估影响: 数千万个

描述: The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'queryString' parameter in the REST API endpoint /ywcas/v1/register in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping.

攻击向量: 网络扫描

CVE编号: CVE-2024-4455

参考链接:


Sudo Baron Samedit - Local Privilege Escalation

  • 漏洞ID: CVE-2021-3156
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

攻击向量: 网络扫描

CVE编号: CVE-2021-3156

参考链接:


PHP - LFR to Remote Code Execution

  • 漏洞ID: CVE-2024-2961
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: PHP Local File Read vulnerability leading to Remote Code Execution

攻击向量: 网络扫描

CVE编号: CVE-2024-2961

参考链接:


HTTP API DOM - XSS on JSONP callback

  • 漏洞ID: CVE-2024-29882
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: SRS is a simple, high-efficiency, real-time video server. SRS's /api/v1/vhosts/vid-&lt;id&gt;?callback&#x3D;&lt;payload&gt; endpoint didn't filter the callback function name which led to injecting malicious javascript payloads and executing XSS ( Cross-Site Scripting). This vulnerability is fixed in 5.0.210 and 6.0.121.

攻击向量: 网络扫描

CVE编号: CVE-2024-29882

参考链接:


SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting

  • 漏洞ID: CVE-2002-1131
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: The Virtual Keyboard plugin for SquirrelMail 1.2.6/1.2.7 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

攻击向量: 网络扫描

CVE编号: CVE-2002-1131

参考链接:


Squirrelmail <=1.4.6 - Local File Inclusion

  • 漏洞ID: CVE-2006-2842
  • 严重程度: 🟠 HIGH
  • 风险等级: 极高风险 (4.5/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: SquirrelMail 1.4.6 and earlier versions are susceptible to a PHP local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. This allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.

攻击向量: 网络扫描

CVE编号: CVE-2006-2842

参考链接:


Zimbra Collaboration - Local File Inclusion

  • 漏洞ID: CVE-2025-68645
  • 严重程度: 🟠 HIGH
  • 风险等级: 高风险 (4/5)
  • 影响资产: 未知
  • 预估影响: 数千个

描述: Zimbra Collaboration (ZCS) 10.0 and 10.1 contain a local file inclusion caused by improper handling of user-supplied parameters in the RestFilter servlet, letting unauthenticated remote attackers include arbitrary files from WebRoot, exploit requires crafted requests to /h/rest endpoint.

攻击向量: 网络扫描

参考链接:


📋 完整模板列表

模板名称严重程度类别影响资产风险评分
Abandoned Cart Lite for WooCommerce - Authenticati🔴 criticalCVE漏洞WordPress 站点5/5
Privileged Remote Access & Remote Support - Comman🔴 criticalCVE漏洞通用5/5
XZ - Embedded Malicious Code🔴 criticalCVE漏洞通用5/5
InvoiceShelf <= 1.3.0 - PHP Deserializatio🔴 criticalCVE漏洞通用5/5
Keras Model.load_model - Arbitrary Code Execution🔴 criticalCVE漏洞通用5/5
GitLab - SAML Authentication Bypass🔴 criticalCVE漏洞GitLab 平台5/5
Horde Groupware Unauthenticated Admin Access🔴 criticalCVE漏洞通用5/5
Kaswara Modern VC Addons <= 3.0.1 - Missin🟠 highCVE漏洞WordPress 站点4.5/5
Kaswara Modern VC Addons <= 3.0.1 - Missin🟠 highCVE漏洞WordPress 站点4.5/5
Ultimate Addons for Elementor <= 1.24.1 -🟠 highCVE漏洞WordPress 站点4.5/5
YITH WooCommerce Ajax Search <= 2.4.0 - Cr🟠 highCVE漏洞WordPress 站点4.5/5
Sudo Baron Samedit - Local Privilege Escalation🟠 highCVE漏洞通用4.5/5
PHP - LFR to Remote Code Execution🟠 highCVE漏洞通用4.5/5
HTTP API DOM - XSS on JSONP callback🟠 highCVE漏洞通用4.5/5
SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting🟠 highCVE漏洞通用4.5/5
Squirrelmail <=1.4.6 - Local File Inclusio🟠 highCVE漏洞通用4.5/5
Zimbra Collaboration - Local File Inclusion🟠 highCVE漏洞通用4/5
WordPress Elementor Website Builder <= 3.5🟡 mediumCVE漏洞WordPress 站点3.5/5
Essential Addons for Elementor < 6.0.15 - Cross🟡 mediumCVE漏洞通用3.5/5
Backdrop CMS - Cross-Site Scripting🟡 mediumCVE漏洞通用3.5/5
Swagger UI >=3.14.1 < 3.38.0 - DOM Base🟡 mediumCVE漏洞通用3.5/5
Microsoft FrontPage Extensions - Information Discl🟡 mediumCVE漏洞通用3.5/5
Jakarta Tomcat 3.1 and 3.0 - Information Disclosur🟡 mediumCVE漏洞通用3.5/5
SquirrelMail 1.4.x - Folder Name Cross-Site Script🟡 mediumCVE漏洞通用3.5/5
Open Bulletin Board (OpenBB) v1.0.6 - Open Redirec🟡 mediumCVE漏洞通用3.5/5
Lotus Domino R5 and R6 WebMail - Information Discl🟡 mediumCVE漏洞通用3.5/5
SquirrelMail Address Add 1.4.2 - Cross-Site Script🟡 mediumCVE漏洞通用3.5/5
SAP Web Application Server 6.x/7.0 - Open Redirect🟡 mediumCVE漏洞通用3.5/5
Cofax <=2.0RC3 - Cross-Site Scripting🟡 mediumCVE漏洞通用3.5/5
Cherokee HTTPD <=0.5 - Cross-Site Scriptin🟡 mediumCVE漏洞通用3.5/5

🛡️ 安全建议

🚨 发现高风险漏洞,建议立即扫描相关资产 🔍 关注新发布的 CVE 漏洞,及时更新补丁 ⚡ 检测到远程代码执行漏洞,优先处理

🔧 扫描建议

建议使用以下 Nuclei 命令进行扫描:

# 扫描高危漏洞
nuclei -t code/cves/2023/CVE-2023-2986.yaml -t code/cves/2024/CVE-2024-12356.yaml -t code/cves/2024/CVE-2024-3094.yaml -t code/cves/2024/CVE-2024-55556.yaml -t code/cves/2025/CVE-2025-1550.yaml -t code/cves/2025/CVE-2025-25291.yaml -t http/cves/2005/CVE-2005-3344.yaml -t http/cves/2021/CVE-2021-4448.yaml -t http/cves/2021/CVE-2021-4448.yaml -t http/cves/2020/CVE-2020-13125.yaml -t http/cves/2024/CVE-2024-4455.yaml -t code/cves/2021/CVE-2021-3156.yaml -t dast/cves/2024/CVE-2024-2961.yaml -t headless/cves/2024/CVE-2024-29882.yaml -t http/cves/2002/CVE-2002-1131.yaml -t http/cves/2006/CVE-2006-2842.yaml -t http/cves/2025/CVE-2025-68645.yaml -u target-url

# 扫描所有今日新增模板  
nuclei -t code/cves/2023/CVE-2023-2986.yaml -t code/cves/2024/CVE-2024-12356.yaml -t code/cves/2024/CVE-2024-3094.yaml -t code/cves/2024/CVE-2024-55556.yaml -t code/cves/2025/CVE-2025-1550.yaml -t code/cves/2025/CVE-2025-25291.yaml -t http/cves/2005/CVE-2005-3344.yaml -t http/cves/2021/CVE-2021-4448.yaml -t http/cves/2021/CVE-2021-4448.yaml -t http/cves/2020/CVE-2020-13125.yaml -t http/cves/2024/CVE-2024-4455.yaml -t code/cves/2021/CVE-2021-3156.yaml -t dast/cves/2024/CVE-2024-2961.yaml -t headless/cves/2024/CVE-2024-29882.yaml -t http/cves/2002/CVE-2002-1131.yaml -t http/cves/2006/CVE-2006-2842.yaml -t http/cves/2025/CVE-2025-68645.yaml -t headless/cves/2022/CVE-2022-29455-headless.yaml -t headless/cves/2025/CVE-2025-24752.yaml -t headless/cves/2025/CVE-2025-25062.yaml -t headless/cves/2025/CVE-2025-8191.yaml -t http/cves/2000/CVE-2000-0114.yaml -t http/cves/2000/CVE-2000-0760.yaml -t http/cves/2004/CVE-2004-0519.yaml -t http/cves/2004/CVE-2004-1965.yaml -t http/cves/2005/CVE-2005-2428.yaml -t http/cves/2005/CVE-2005-3128.yaml -t http/cves/2005/CVE-2005-3634.yaml -t http/cves/2005/CVE-2005-4385.yaml -t http/cves/2006/CVE-2006-1681.yaml -u target-url

本报告基于 Nuclei 模板库自动生成,数据来源:ProjectDiscovery/nuclei-templates

扫描建议仅供参考,请在授权环境下进行安全测试

文章目录