« Volver al listado

Projectdiscovery

Projectdiscovery Nuclei: vulnerabilidades y CVE

Projectdiscovery Nuclei tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses8
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-76805Media (5.3)0.41%—22 sept 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second…
CVE-2026-76804Media (5.5)0.17%—22 sept 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates…
CVE-2026-76803Media (5.3)0.40%—22 sept 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the…
CVE-2026-76802Media (4.7)0.18%—22 sept 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that…
CVE-2026-92718Alta (7)0.12%—16 sept 2026
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore…
CVE-2026-41646Media (5.5)0.16%—8 may 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and…
CVE-2026-41645Media (5.3)0.44%—8 may 2026
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to…
CVE-2026-41282Alta (7.5)0.43%—20 abr 2026
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
CVE-2024-43405Alta (7.8)1.1%—4 sept 2024
Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to…
CVE-2024-40641Alta (7.4)0.31%—17 jul 2024
Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web…
CVE-2024-27920Alta (7.4)0.41%—15 mar 2024
projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates…
CVE-2023-37896Alta (7.5)1.0%—4 ago 2023
Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution5
  2. T1005 Data from Local System3
  3. T1059 Command and Scripting Interpreter2
  4. T1190 Exploit Public-Facing Application1
  5. T1553.006 Code Signing Policy Modification1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Projectdiscovery