Projectdiscovery

Nuclei

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 22.09.2026 16:48:49
  • Zuletzt bearbeitet 23.09.2026 18:28:25

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allows response ...

  • EPSS 0.18%
  • Veröffentlicht 22.09.2026 16:47:00
  • Zuletzt bearbeitet 24.09.2026 21:20:08

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block an...

  • EPSS 0.17%
  • Veröffentlicht 22.09.2026 16:41:46
  • Zuletzt bearbeitet 28.09.2026 20:17:10

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted ...

  • EPSS 0.4%
  • Veröffentlicht 22.09.2026 16:27:59
  • Zuletzt bearbeitet 26.09.2026 00:16:35

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option. An untrus...

  • EPSS 0.11%
  • Veröffentlicht 16.09.2026 17:31:38
  • Zuletzt bearbeitet 24.09.2026 21:04:40

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to...

  • EPSS 0.34%
  • Veröffentlicht 08.05.2026 03:17:19
  • Zuletzt bearbeitet 08.05.2026 19:42:49

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported D...

  • EPSS 0.11%
  • Veröffentlicht 08.05.2026 03:14:49
  • Zuletzt bearbeitet 08.05.2026 19:42:59

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require(...

  • EPSS 0.25%
  • Veröffentlicht 20.04.2026 07:10:30
  • Zuletzt bearbeitet 23.04.2026 15:25:04

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

  • EPSS 1.12%
  • Veröffentlicht 04.09.2024 16:15:06
  • Zuletzt bearbeitet 01.10.2024 15:37:37

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature check and poss...

  • EPSS 0.31%
  • Veröffentlicht 17.07.2024 18:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nuclei and allo...