Skip to main content

Vendor/product archive

projectdiscovery / nuclei CVEs

Beta · best-effort

6 CVEs tagged to projectdiscovery / nuclei0 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-41646

Published May 8, 2026

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows Java…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41645

Published May 8, 2026

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it p…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-41282

Published Apr 20, 2026

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configura…

CVSS 4.0 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2024-43405

Published Sep 4, 2024

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verificatio…

CVSS 7.4 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2024-27920

Published Mar 15, 2024

projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37896

Published Aug 4, 2023

Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1