VendorsProjectDiscoverynucleiall versions
Vulnerabilities

ProjectDiscovery Nuclei

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-43405
Nuclei Template Signature Verification Bypass
Published 2024-09-04 · Analyzed
7.8EPSS 0.011
CVE-2023-37896
Nuclei Path Traversal vulnerability
Published 2023-08-04 · Modified
7.5EPSS 0.010
CVE-2026-41282
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
Published 2026-04-20 · Analyzed
7.5EPSS 0.004
CVE-2024-27920
Unsigned code template execution through workflows in projectdiscovery/nuclei
Published 2024-03-15 · Analyzed
7.4EPSS 0.004
CVE-2026-41646
Nuclei: Local File Read via require() Module Loader Bypass
Published 2026-05-08 · Analyzed
5.5EPSS 0.002
CVE-2026-41645
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
Published 2026-05-08 · Analyzed
5.3EPSS 0.004