Nuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.

Nuclei just crossed 30,000 stars. Thank you to everyone who starred it, wrote a template, filed an issue, or shipped a fix. This one belongs to the community.
1
4
24
7,001
Scanning for CVE-2025-68613 using Nuclei If you're running self-hosted n8n, scan your apps now. Works without credentials (version check) and with credentials (RCE check) Nuclei Template - cloud.projectdiscovery.io/li… Vulnerability Advisory - github.com/n8n-io/n8n/securi… #n8n #cybersecurity
1
10
31
8,563
Scanning for CVE-2025-55182 using @pdnuclei 🚨 If you're running Next.js / React, scan your apps now. Nuclei Template - cloud.projectdiscovery.io/li… Vulnerability Advisory - react.dev/blog/2025/12/03/cr… #nextjs #cybersecurity #react2shell
2
78
400
31,955
🚨 CVE-2025-0133 – Reflected XSS in PAN-OS Affects Palo Alto firewalls. Issued just 6 days ago. Nuclei detection template is now live ⚡️ #xss #infosec #security #bugbounty #paloalto
3
9
115
18,816
🚨 CVE-2025-49113 – Authenticated RCE in Roundcube via unsafe deserialization in upload.php (via @FearsOff) PoC-based detection template and full details in comments.
2
69
352
31,551
🚨 New Critical CVE Alert: CVE-2025-31324 🚨 Scan for SAP NetWeaver Metadata Uploader - Unauthenticated Deserialization using @pdnuclei 🔗 Detection templates in comment 👇 #hackwithautomation #sap #infosec
1
49
204
19,189
In Nuclei-Templates, we don’t just add CVEs — we continuously update them to reduce false negatives and introduce regular enhancements 🛠️ Recently, we added IngressNightmare (CVE-2025-1974). Today, we’ve updated it and expanded coverage by adding the following related vulnerabilities: - CVE-2025-1098 – Ingress-Nginx Controller: "Configuration Injection via unsanitized mirror annotations" - CVE-2025-1097 – Ingress-Nginx Controller: "Configuration Injection via unsanitized auth-tls-match-cn annotation" - CVE-2025-24514 – Ingress-Nginx Controller: "Configuration Injection via unsanitized auth-url annotation" These additions help ensure comprehensive detection across affected versions of Ingress-Nginx 🔍 #cve #k8s #IngressNightmare
16
74
5,039
🚨 CrushFTP Authentication Bypass (CVE-2025-2825) A critical auth bypass in CrushFTP 10.0.0–10.8.3 and 11.0.0–11.3.0 allows remote attackers to gain full access using S3-style headers. The flaw stems from improper handling of authentication flags—letting attackers completely bypass login checks. 🔥 Impact: Full unauthenticated server access 🔍 Detection: Nuclei template to identify vulnerable instances 🛠️ Fix: Upgrade to the latest secure version immediately 📖 Technical Deep Dive 👇
2
2
6
1,549
Happy Holidays from ProjectDiscovery! 🎉✨ As we wrap up another incredible year, we want to express our heartfelt gratitude to our amazing community. Your passion, collaboration, and support drive everything we do. May your holidays be filled with joy, and may the new year bring success, innovation, and security to all your endeavors. Together, we’ll continue to build a safer and more connected digital world in 2025. Here’s to a fantastic year ahead! 🥂 Cheers, The ProjectDiscovery Team #HappyHolidays #CyberSecurity #CommunityMatters #ProjectDiscovery
2
19
1,646
Detect Mitel MiCollab - Authentication Bypass (CVE-2024-41713) & Arbitary File Read with Nuclei 🚀 👉 cloud.projectdiscovery.io/?t… 👉 cloud.projectdiscovery.io/?t… Nuclei Templates by @DhiyaneshDK Research: labs.watchtowr.com/where-the… by @watchtowrcyber #hackwithautomation #Cybersecurity #AppSec #BugBounty
14
72
4,831
Detect Sitecore RCE (CVE-2024-46938) with Nuclei 🚀 🔹 Nuclei Template: cloud.projectdiscovery.io/?t… by @DhiyaneshDK 🔹 Research: assetnote.io/resources/resea… by @assetnote #hackwithautomation #Cybersecurity #AppSec #BugBounty
2
68
277
19,593
Scan for CVE-2024-47176 (CUPS - Remote Code Execution) with Nuclei Vulnerability discovery and analysis by @evilsocket: evilsocket.net/2024/09/26/At… Nuclei Template: cloud.projectdiscovery.io/?t… #hackwithautomation #cybersecurity #bugbounty
1
113
556
42,555
🚨 New Vulnerability Analysis: Zimbra Collaboration Suite < 9.0.0 is vulnerable to Remote Code Execution (CVE-2024-45519). Our latest blog details the impact and analysis of this vulnerability and includes a Nuclei template for detection. 🔗 Analysis & Template: blog.projectdiscovery.io/zim… 🔗 Zimbra Security Advisories: wiki.zimbra.com/wiki/Zimbra_… Secure your infrastructure now! #hackwithautomation #cybersecurity #bugbounty
21
71
11,641
Don't forget, the September PD Livestream is tomorrow at 3pm UTC! Join Georgina and Jason for discussions around our community and program initiatives - we can't wait to see you there! buff.ly/47ugmse
1
937
Check out the latest blog - Azure Config Review - Nuclei Templates v10.0.0 🎉 - from ProjectDiscovery! buff.ly/4djspdf #hackwithautomation #opensource #bugbounty #appsec #security
13
54
3,381
🚀 Nuclei v3.3.1 is out! New features include: ➡️ Senstive data reduction from output. ➡️ Result upload to cloud team dashboard. ➡️ Multiple bug fixes. Docs for result upload to teams - docs.projectdiscovery.io/clo… Check the full release for details - github.com/projectdiscovery/… #CyberSecurity #OpenSource #Bugbounty
5
30
7,793
Check out the latest blog - Introducing the httpx dashboard - from ProjectDiscovery! buff.ly/46CmcHx #hackwithautomation #opensource #bugbounty #appsec #security
5
32
3,069
Don't forget, we're hosting #DiscoveryHours at #DefCon tonight from 7pm-10pm PDT! If you're already registered, please check your email for further details on the location. Limited tickets left - we'll see you there! buff.ly/3WKcSgi
6
965
Check out the latest blog - Advancing Asset Management - PDCP v0.8.9 - from ProjectDiscovery! buff.ly/3YzYWI7 #hackwithautomation #opensource #bugbounty #appsec #security
2
14
1,847
Query your entire tech stack to streamline vulnerability assessment using AI. Upgrade your workflows today: buff.ly/3yqD7QC #appsec #asm #security #cybersecurity
1
22
2,322
Check out the latest blog - July 2024 Newsletter - from ProjectDiscovery! buff.ly/3Ae8AWy #hackwithautomation #opensource #bugbounty #appsec #security
4
1,142
🤝 Connect with the ProjectDiscovery team at Defcon 🌆! Grab a drink with CTO Sandeep (@emgeekboy) and the minds behind your favorite open-source security tools while picking up some PD swag. 🍹🔐 Limited spots available, RSVP: buff.ly/3zZwFR4
1
6
1,316
🚀 Excited to announce the ProjectDiscovery Meetup & Happy Hour at Defcon on Thurs, 8th August 🎉 Join us for an evening of open-source security tools, networking, and fun 🛠️🍻 (and exclusive PD swag 🧢). Limited spots available - RSVP now: buff.ly/3zZwFR4 #OpenSource
1
2
1,332
Check out the latest blog - Enhancing Asset Discovery: ProjectDiscovery Cloud Platform v0.8.8 - from ProjectDiscovery! buff.ly/4cBkE2x #hackwithautomation #opensource #bugbounty #appsec #security
3
1,183
Check out the latest blog - June 2024 Newsletter - from ProjectDiscovery! buff.ly/3LtkJJX #hackwithautomation #opensource #bugbounty #appsec #security
1
1
1
1,159
Check out the latest blog - May 2024 Newsletter - from ProjectDiscovery! buff.ly/3W7Gzsv #hackwithautomation #opensource #bugbounty #appsec #security
1
2
1,058
Check out the latest blog - Kubernetes Cluster Security - Nuclei Templates v9.9.0 🎉 - from ProjectDiscovery! buff.ly/45GLl3p #hackwithautomation #opensource #bugbounty #appsec #security
5
22
1,867
Check out the latest blog - PDCP v0.8.7: Enhanced Team Management, 2FA, and Asset Filtering - from ProjectDiscovery! buff.ly/4c87FVJ #hackwithautomation #opensource #bugbounty #appsec #security
1
10
2,022
🚨 Scan for PHP CGI Argument Injection vulnerability (CVE-2024-4577) discovered by @orange_8361 using Nuclei templates! 🔍 Details: devco.re/blog/2024/06/06/sec… 📑 Nuclei Template: cloud.projectdiscovery.io/pu… 🔧 GitHub PR: github.com/projectdiscovery/… #hackwithautomation #bugbounty #appsec
52
206
15,500
Today, we are introducing a new way to run blazing fast vulnerability scans at scale, effortlessly. Try our early BETA for free now! nux.gg/try-platform
12
61
6,021
Detect CVE-2024-24919 using nuclei templates shared by @johnk3r Shared Template URL - cloud.projectdiscovery.io/@s… #hackwithautomation #appsec #bugbounty #cybersecurity
7
67
7,443
Check out the latest blog - Understand the cloud security attack surface - from ProjectDiscovery! buff.ly/4bCzsNP #hackwithautomation #opensource #bugbounty #appsec #security
1
1
1,320
After publishing Nuclei templates for AWS security checks, our template team is now working on publishing Nuclei templates for Kubernetes cluster security. See ongoing progress at github.com/projectdiscovery/… and share any feedback. #cloudsecurity #k8s #CyberSecurity
2
36
200
14,661
Check out the latest blog - What is vulnerability management? And how can ProjectDiscovery help? - from ProjectDiscovery! buff.ly/3yDztCw #hackwithautomation #opensource #bugbounty #appsec #security
3
7
1,393
Check out the latest blog - What is attack surface management? - from ProjectDiscovery! buff.ly/3ykDWKi #hackwithautomation #opensource #bugbounty #appsec #security
8
1,988
👏👏👏 Let’s celebrate our first-time contributors!
1
1,028
Scan for latest CVE-2023-47246 (SysAid Server - Remote Code Execution) using nuclei templates Template: github.com/projectdiscovery/… Advisory: sysaid.com/blog/service-desk… #hackwithautomation #appsec #bugbounty #cybersecurity
1
38
150
22,950
Scan for F5 BIG-IP - Unauthenticated RCE via AJP Smuggling (CVE-2023-46747) using nuclei templates shared by @iamnoooob @rootxharsh Template - github.com/projectdiscovery/… Analysis - praetorian.com/blog/refresh-… by @praetorianlabs Advisory - my.f5.com/manage/s/article/K… #hackwithautomation #security #f5 #bugbounty
4
164
489
71,298
New updates to Nuclei Template Editor: 👉 Displays debug data for failed matches (useful for template creation + debugging) 👉Minor UI Improvements. Template Editor - templates.nuclei.sh
1
7
51
8,005
5 Minute Hacks: Credential Stuffing with Nuclei ⚛️ Learn how to use nuclei credential stuffing templates for pitchfork and clusterbomb attacks as well as how to protect against them! Watch now 👇 #nuclei101 #hacking #HackWithAutomation youtu.be/ePT80REfJ8k
5
14
2,279
Fastest zero-day templates (from announcement to template) ⏱ 🥉 @DhiyaneshDK: CVE-2020-36289 < 30 minutes 🥈 @DhiyaneshDK: CVE-2023-29489 < 15 minutes 🥇 @johnk3r: CVE-2023-2448 < 10 minutes Can you beat this?
6
4
52
12,984
🆕 Critical Template Alert 🚨 Detect CVE in Ivanti MobileIron Sentry (<= v9.18.0) affecting MICS Admin Portal. The flaw may allow attackers to bypass authentication controls on the admin interface due to weak Apache HTTPD config. Check it out 👇 🔗 github.com/projectdiscovery/…
20
57
7,944
Automate TLS network requests with Nuclei! 🤖 🤘 By adding a tls:// schema at the start of the hostname you can send encrypted TCP connections effortlessly! Check out this basic TLS template to get started 👇 #nuclei101 #hackwithautomation
5
15
3,723
An introduction to using Nuclei filters with @pwnfunction! 🧑‍🏫 ⚛️ The Basics ⚛️ Template Inclusion/Exclusion ⚛️ Nuclei's Domain Specific Language(DSL) ⚛️ Custom Filter Fields Watch now 👇 #nuclei101 #hackwithautomation youtu.be/CRRURPkfOIs
5
16
3,929
Level up your security assessments with Nuclei's raw TCP support! Think of it as an automatable Netcat. Here's a basic template below for sending raw TCP requests 👇
1
3
8
3,061
Send raw hex data to network services, and fine-tune your security assessments! ⚛️ 🔢 Check out this Hex Input Network Request template, where you can encode your "PING" in hex and look for the "PONG" response! 👇 #nuclei101 #hackwithautomation #hexencoding
3
6
2,259
💡 DSL extractors DSL extractors can extract data using DSL expressions such as to extracting the effective body length through the len helper function from HTTP Response! 👇 🧵 6/6
1
1
2
1,519
🌐 Xpath extractors Xpath extractors work with HTML such as extracting 'href' attribute values 👇 💡 Tip: You can get xpath values from any webpage content by copying it to the browser. 🧵 5/6
1
2
1,171
🔍 JSON extractors JSON extractors help extract data from JSON responses. This example 👇 extracts the value of 'id' object from JSON block. (Learn more on JQ - github.com/stedolan/jq) 🧵 4/6
1
1
267
🔑 Kval extractors Kval extractors work with key:value formatted data. Here's an example to extract the content-type header from HTTP response 👇 (NOTE: Dash (-) is replaced with underscore (_) because kval doesn't accept dash) 🧵 3/6
1
1
254
🔢 Regex extractors Regex extractors use regular expressions to extract data 👇 🧵2/6
1
1
258
A quick guide to the 5 types of nuclei extractors: ⚛️ regex ⚛️ kval ⚛️ json ⚛️ xpath ⚛️ dsl Details in the thread 🧵👇
1
13
48
12,120
Did you know you can forward your results to @splunk HEC? All you need to do is create a config file with the following content and replace the appropriate values! 🔥 #nuclei101 #hackwithautomation #nucleitemplates
1
3
20
4,044
3 steps to Integrate Nuclei into your GitLab CI/CD pipeline 🤝 1️⃣ Create a new GitLab repository 2️⃣ Configure Pipeline to create a “.gitlab-ci.yml file 3️⃣ Put the below workflow code in the ".gitlab-ci.yml” file and save it 👇 Full walkthrough: 👉 🔗 blog.projectdiscovery.io/imp…
11
57
6,019
🔥HOT🔥 Tip: Combine multiple filters with the template condition flag (-tc)! This allows for complex expressions like the ones below 👇 #nuclei101 #hackwithautomation #security
21
80
9,722
How to implement rate limiting with nuclei ⚛️ In this example we restrict outgoing requests to: 🐢 3 per second: -rl 3 🐢 2 concurrent templates: -c 2 🔥 TIP: Use these options to avoid disrupting target availability or address bandwidth issues! #nuclei101
1
27
70
9,025
Everything you need to know about nuclei filters! ⚛️ 🏷 From tags to severity to authors, this quick start guide will get you on your way to writing your own custom templates in no time! Read now 👉🔗 nuclei.projectdiscovery.io/n… #Nuclei101 #Hackwithautomation #Nucleitemplates
7
25
3,769
[RELEASE-UPDATE] Nuclei v2.9.13 🚀 🌟 Run public / shared templates from templates.nuclei.sh with nuclei 🌟 Added xpath matcher support. 🌟 Security fixes for headless templates. More details 📖 - github.com/projectdiscovery/… #hackwithautomation #opensource #cybersecurity
7
32
5,027