github.com/projectdiscovery/nuclei
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/projectdiscovery/nucleipage 1 of 1
- CVE-2023-37896HIGHCVSS 7.5EG 7.5✓ Fixed in 2.9.92023-08-04
Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The problem was related to sa…
- CVE-2024-27920HIGHCVSS 7.4EG 7.42024-03-15
projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates through workflows. Th…
- CVE-2024-40641HIGHCVSS 7.4EG 7.42024-07-17
Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nucl…
- CVE-2024-43405HIGHCVSS 7.4EG 7.42024-09-04
Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature che…
- CVE-2026-41646MEDIUMCVSS 5.5EG 5.52026-05-08
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through t…
Check whether github.com/projectdiscovery/nuclei is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/projectdiscovery/nuclei CVEs against the assets you own.
Start Free Scan →