Nuclei
Projectdiscovery · 12 CVEs
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
Sep 22, 2026
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
Sep 22, 2026
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Sep 22, 2026
Nuclei: Local File Read via MySQL Client Sandbox Bypass
Sep 22, 2026
Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache
Sep 16, 2026
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
May 8, 2026
Nuclei: Local File Read via require() Module Loader Bypass
May 8, 2026
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step te…
Apr 20, 2026
Nuclei Template Signature Verification Bypass
Sep 4, 2024
Unsigned code template execution through workflows in projectdiscovery/nuclei
Jul 17, 2024
Unsigned code template execution through workflows in projectdiscovery/nuclei
Mar 15, 2024
Nuclei Path Traversal vulnerability
Aug 4, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-76805 | Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode | MEDIUM | 0.41% | Sep 22, 2026 |
| CVE-2026-76802 | Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass | MEDIUM | 0.18% | Sep 22, 2026 |
| CVE-2026-76804 | Nuclei: Local File Read via Workflow File-Protocol Gate Bypass | MEDIUM | 0.17% | Sep 22, 2026 |
| CVE-2026-76803 | Nuclei: Local File Read via MySQL Client Sandbox Bypass | MEDIUM | 0.40% | Sep 22, 2026 |
| CVE-2026-92718 | Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache | HIGH | 0.12% | Sep 16, 2026 |
| CVE-2026-41645 | Nuclei: Environment variable disclosure via Response-Derived DSL Expressions | MEDIUM | 0.44% | May 8, 2026 |
| CVE-2026-41646 | Nuclei: Local File Read via require() Module Loader Bypass | MEDIUM | 0.16% | May 8, 2026 |
| CVE-2026-41282 | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not t… | HIGH | 0.43% | Apr 20, 2026 |
| CVE-2024-43405 | Nuclei Template Signature Verification Bypass | MEDIUM | 1.11% | Sep 4, 2024 |
| CVE-2024-40641 | Unsigned code template execution through workflows in projectdiscovery/nuclei | HIGH | 0.31% | Jul 17, 2024 |
| CVE-2024-27920 | Unsigned code template execution through workflows in projectdiscovery/nuclei | HIGH | 0.41% | Mar 15, 2024 |
| CVE-2023-37896 | Nuclei Path Traversal vulnerability | HIGH | 1.05% | Aug 4, 2023 |
Showing 1 to 12 of 12 CVEs