Nuclei just crossed 30,000 stars.
Thank you to everyone who starred it, wrote a template, filed an issue, or shipped a fix. This one belongs to the community.
🚨 CVE-2025-0133 – Reflected XSS in PAN-OS
Affects Palo Alto firewalls. Issued just 6 days ago.
Nuclei detection template is now live ⚡️
#xss#infosec#security#bugbounty#paloalto
🚨 CVE-2025-49113 – Authenticated RCE in Roundcube via unsafe deserialization in upload.php (via @FearsOff)
PoC-based detection template and full details in comments.
🚨 New Critical CVE Alert: CVE-2025-31324 🚨
Scan for SAP NetWeaver Metadata Uploader - Unauthenticated Deserialization using @pdnuclei
🔗 Detection templates in comment 👇
#hackwithautomation#sap#infosec
In Nuclei-Templates, we don’t just add CVEs — we continuously update them to reduce false negatives and introduce regular enhancements 🛠️
Recently, we added IngressNightmare (CVE-2025-1974). Today, we’ve updated it and expanded coverage by adding the following related vulnerabilities:
- CVE-2025-1098 – Ingress-Nginx Controller: "Configuration Injection via unsanitized mirror annotations"
- CVE-2025-1097 – Ingress-Nginx Controller: "Configuration Injection via unsanitized auth-tls-match-cn annotation"
- CVE-2025-24514 – Ingress-Nginx Controller: "Configuration Injection via unsanitized auth-url annotation"
These additions help ensure comprehensive detection across affected versions of Ingress-Nginx 🔍
#cve#k8s#IngressNightmare
🚨 CrushFTP Authentication Bypass (CVE-2025-2825)
A critical auth bypass in CrushFTP 10.0.0–10.8.3 and 11.0.0–11.3.0 allows remote attackers to gain full access using S3-style headers. The flaw stems from improper handling of authentication flags—letting attackers completely bypass login checks.
🔥 Impact: Full unauthenticated server access
🔍 Detection: Nuclei template to identify vulnerable instances
🛠️ Fix: Upgrade to the latest secure version immediately
📖 Technical Deep Dive 👇
Happy Holidays from ProjectDiscovery! 🎉✨
As we wrap up another incredible year, we want to express our heartfelt gratitude to our amazing community. Your passion, collaboration, and support drive everything we do.
May your holidays be filled with joy, and may the new year bring success, innovation, and security to all your endeavors. Together, we’ll continue to build a safer and more connected digital world in 2025.
Here’s to a fantastic year ahead! 🥂
Cheers,
The ProjectDiscovery Team
#HappyHolidays#CyberSecurity#CommunityMatters#ProjectDiscovery
🚨 New Vulnerability Analysis: Zimbra Collaboration Suite < 9.0.0 is vulnerable to Remote Code Execution (CVE-2024-45519).
Our latest blog details the impact and analysis of this vulnerability and includes a Nuclei template for detection.
🔗 Analysis & Template: blog.projectdiscovery.io/zim…
🔗 Zimbra Security Advisories: wiki.zimbra.com/wiki/Zimbra_…
Secure your infrastructure now!
#hackwithautomation#cybersecurity#bugbounty
Don't forget, the September PD Livestream is tomorrow at 3pm UTC!
Join Georgina and Jason for discussions around our community and program initiatives - we can't wait to see you there! buff.ly/47ugmse
Don't forget, we're hosting #DiscoveryHours at #DefCon tonight from 7pm-10pm PDT!
If you're already registered, please check your email for further details on the location. Limited tickets left - we'll see you there! buff.ly/3WKcSgi
🤝 Connect with the ProjectDiscovery team at Defcon 🌆! Grab a drink with CTO Sandeep (@emgeekboy) and the minds behind your favorite open-source security tools while picking up some PD swag. 🍹🔐 Limited spots available, RSVP: buff.ly/3zZwFR4
🚀 Excited to announce the ProjectDiscovery Meetup & Happy Hour at Defcon on Thurs, 8th August 🎉 Join us for an evening of open-source security tools, networking, and fun 🛠️🍻 (and exclusive PD swag 🧢). Limited spots available - RSVP now: buff.ly/3zZwFR4#OpenSource
Today, we are introducing a new way to run blazing fast vulnerability scans at scale, effortlessly. Try our early BETA for free now!
nux.gg/try-platform
After publishing Nuclei templates for AWS security checks, our template team is now working on publishing Nuclei templates for Kubernetes cluster security.
See ongoing progress at github.com/projectdiscovery/… and share any feedback.
#cloudsecurity#k8s#CyberSecurity
ALT New Contributors
• @Christbowel made their first contribution in #9181
@bmcxxx made their first contribution in #9225
• @zyrnj made their first contribution in #9235
• @g33gs made their first contribution in #9211
@NeckBeardPrince made their first contribution in #9255
@JPGOmez made their first contribution in #9271
• @trolldbois made their first contribution in #9289
@Michal-Mikolas made their first contribution in #9282
5 Minute Hacks: Credential Stuffing with Nuclei ⚛️
Learn how to use nuclei credential stuffing templates for pitchfork and clusterbomb attacks as well as how to protect against them!
Watch now 👇 #nuclei101#hacking#HackWithAutomationyoutu.be/ePT80REfJ8k
🆕 Critical Template Alert 🚨
Detect CVE in Ivanti MobileIron Sentry (<= v9.18.0) affecting MICS Admin Portal.
The flaw may allow attackers to bypass authentication controls on the admin interface due to weak Apache HTTPD config.
Check it out 👇
🔗 github.com/projectdiscovery/…
Automate TLS network requests with Nuclei! 🤖
🤘 By adding a tls:// schema at the start of the hostname you can send encrypted TCP connections effortlessly!
Check out this basic TLS template to get started 👇
#nuclei101#hackwithautomation
Level up your security assessments with Nuclei's raw TCP support!
Think of it as an automatable Netcat.
Here's a basic template below for sending raw TCP requests 👇
Send raw hex data to network services, and fine-tune your security assessments! ⚛️
🔢 Check out this Hex Input Network Request template, where you can encode your "PING" in hex and look for the "PONG" response! 👇
#nuclei101#hackwithautomation#hexencoding
💡 DSL extractors
DSL extractors can extract data using DSL expressions such as to extracting the effective body length through the len helper function from HTTP Response! 👇
🧵 6/6
🌐 Xpath extractors
Xpath extractors work with HTML such as extracting 'href' attribute values 👇
💡 Tip: You can get xpath values from any webpage content by copying it to the browser.
🧵 5/6
🔍 JSON extractors
JSON extractors help extract data from JSON responses.
This example 👇 extracts the value of 'id' object from JSON block.
(Learn more on JQ - github.com/stedolan/jq)
🧵 4/6
🔑 Kval extractors
Kval extractors work with key:value formatted data.
Here's an example to extract the content-type header from HTTP response 👇
(NOTE: Dash (-) is replaced with underscore (_) because kval doesn't accept dash)
🧵 3/6
Did you know you can forward your results to @splunk HEC?
All you need to do is create a config file with the following content and replace the appropriate values! 🔥
#nuclei101#hackwithautomation#nucleitemplates
3 steps to Integrate Nuclei into your GitLab CI/CD pipeline 🤝
1️⃣ Create a new GitLab repository
2️⃣ Configure Pipeline to create a “.gitlab-ci.yml file
3️⃣ Put the below workflow code in the ".gitlab-ci.yml” file and save it 👇
Full walkthrough:
👉 🔗 blog.projectdiscovery.io/imp…
🔥HOT🔥 Tip: Combine multiple filters with the template condition flag (-tc)!
This allows for complex expressions like the ones below 👇
#nuclei101#hackwithautomation#security
How to implement rate limiting with nuclei ⚛️
In this example we restrict outgoing requests to:
🐢 3 per second: -rl 3
🐢 2 concurrent templates: -c 2
🔥 TIP: Use these options to avoid disrupting target availability or address bandwidth issues! #nuclei101