Skip to content

Releases: projectdiscovery/nuclei-templates

v9.5.4

02 Jul 17:57
Compare
Choose a tag to compare

What's Changed

New Templates Added : 51

New CVEs Added: 26

New Contributors

Full Changelog: v9.5.3...v9.5.4

v9.5.3

21 Jun 04:24
Compare
Choose a tag to compare

🔥 Highlights of this release:

✅ [CVE-2023-34362] MOVEit Transfer - Remote Code Execution (@princechaddha,@rootxharsh,@ritikchaddha,@pdresearch) [critical]
✅ [CVE-2023-34960] Chamilo Command Injection (@dhiyaneshdk) [high]
✅ [CVE-2023-33246] RocketMQ <= 5.1.0 - Remote Code Execution (@iamnoooob,@rootxharsh,@pdresearch) [critical]
✅ [CVE-2023-25157] GeoServer OGC Filter - SQL Injection (@ritikchaddha,@dhiyaneshdk,@iamnoooob,@rootxharsh) [critical]
✅ [CVE-2023-23333] SolarView Compact 6.00 - OS Command Injection (@Mr-xn) [critical]
✅ [CVE-2023-20887] VMware VRealize Network Insight - Remote Code Execution (@sinsinology) [critical]
✅ [CVE-2022-23544] MeterSphere < 2.5.0 SSRF (@j4vaovo) [medium]
✅ [CVE-2022-24706] CouchDB Erlang Distribution - Remote Command Execution (@Mzack9999,@pussycat0x) [critical]
✅ [CVE-2017-12617] Apache Tomcat - Remote Code Execution (@pussycat0x) [high]
✅ [CVE-2016-6195] vBulletin <= 4.2.3 - SQL Injection (@mastercho) [high]

What's Changed

New Templates Added: 62

New CVEs Added: 28

New Contributors

Full Changelog: v9.5.2...v9.5.3

v9.5.2 [Credential Stuffing Templates]

05 Jun 10:33
Compare
Choose a tag to compare

🔥 Highlights of this release:

This release adds a collection of credential-stuffing templates for both cloud and self-hosted services. These templates can be used for automating the identification and prevention of credential stuffing attempts across your organization's websites and applications.

Credential Stuffing Templates:

What's Changed

New Templates Added : 44

New CVEs Added: 29

New Contributors

Full Changelog: v9.5.1...v9.5.2

v9.5.1

01 Jun 09:14
Compare
Choose a tag to compare

🔥 Highlights of this release:

✅ [CVE-2023-32243] WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset (@dhiyaneshdk) [critical]
✅ [CVE-2023-29923] PowerJob <=4.3.2 - Unauthenticated Access (@For3stCo1d) [medium]
✅ [CVE-2023-25717] Ruckus Wireless Admin - Remote Code Execution (@parthmalhotra,@pdresearch) [critical]
✅ [CVE-2023-2825] GitLab 16.0.0 - Path Traversal (@dhiyaneshdk,@rootxharsh,@iamnoooob,@pdresearch) [critical]
✅ [CVE-2023-2732] MStore API <= 3.9.2 - Authentication Bypass (@dhiyaneshdk) [critical]
✅ [CVE-2021-39165] Cachet <=2.3.18 - SQL Injection (@tess) [high]
✅ [CVE-2020-29583] ZyXel USG - Hardcoded Credentials (@canberbamber) [critical]
✅ [CVE-2020-1956] Apache Kylin 3.0.1 - Command Injection (@iamnoooob,@rootxharsh,@pdresearch) [high]
✅ [CVE-2016-3510] Oracle WebLogic Server - Remote Code Execution (@iamnoooob,@rootxharsh,@pdresearch) [critical]

What's Changed

New Templates Added: 56
New CVEs Added: 23

New Contributors

Full Changelog: v9.5.0...v9.5.1

Nuclei Templates v9.5.0 (breaking changes)

11 May 15:32
Compare
Choose a tag to compare

Release Highlight:

  1. Nuclei Templates Refactoring: organized and categorized directory structure for improved management of nuclei templates.
  2. Enhanced CVE Templates: more comprehensive vulnerability analysis with added information like CPE and EPSS Score.
  3. Template Metadata: auto-generated max-request counter to each template, allowing easy filtering and visibility of maximum request.
  4. Log4j Templates Update: updated templates addressing potential false positives related to Log4j.
  5. KEV & Trending CVEs: a curated selection of noteworthy Known Exploited Vulnerabilities (KEV) and Trending CVEs, highlighted with 🔥.

See nuclei-templates v9.5.0, projectdiscovery/nuclei#3648, https://blog.projectdiscovery.io/nuclei-template-v9-5-0-update/ for more details.


New Templates Added : 61

New Contributors

Full Changelog: v9.4.3...v9.4.4

v9.4.3

24 Apr 04:52
Compare
Choose a tag to compare

What's Changed

New Templates Added: 55

New Contributors

Full Changelog: v9.4.2...v9.4.3

v9.4.2

09 Apr 03:16
Compare
Choose a tag to compare

What's Changed

New Templates Added: 78

New Contributors

Full Changelog: v9.4.1...v9.4.2

v9.4.1

27 Mar 06:41
Compare
Choose a tag to compare

What's Changed

New Templates Added : 69

New Contributors

Full Changelog: v9.4.0...v9.4.1

v9.4.0

18 Mar 09:14
Compare
Choose a tag to compare

What's Changed

New Templates Added: 65

New Contributors

Full Changelog: v9.3.9...v9.4.0

v9.3.9

10 Mar 18:42
Compare
Choose a tag to compare

What's Changed

New Templates Added : 61

New Contributors

Full Changelog: v9.3.8...v9.3.9