Skip to content
Nuclei

Nuclei

projectdiscovery.io • June 4, 2026

Nuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.

ProjectDiscovery responds to critical vulnerabilities faster than legacy scanners.

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Kubernetes and Wiz Research publicly disclosed CVE-2025-1974 and released patched Ingress NGINX versions 1.12.1 and 1.11.5.

A Nuclei template for internal network scanning of CVE-2025-1974 was released, enabling detection within private infrastructures.

Qualys released a blog post recommending users upgrade their Ingress NGINX controller to the patched versions to mitigate CVE-2025-1974.

A Nuclei template for external scanning was released, allowing detection of CVE-2025-1974 from outside target networks.

Rapid7 launched the Kubernetes Cluster Scanner plugin with checks for CVE-2025-1974, enabling customers to validate patch status across their clusters.

Tenable published a direct remote check plugin for Nessus, allowing automated scanning for CVE-2025-1974 on target systems.

Leverage the global security community to streamline your vulnerability management. With a template library full of contributions from pentest, bug bounty, and security teams to automate the most complex vulnerability detection.

Broken Authentication

Run the vulnerability tests as an attacker would to exploit a given vulnerability. Capture full logs behind a given test to triage faster for the team.

Use our AI-powered vulnerability automation editor to convert your internal vulnerability data into an automated detection pipeline.

Nuclei, built by our team , supports over 6 protocols as well as code protocols, so you can basically stitch almost any kind of vulnerability.

Recognizing members who are making an impact on internet security.

Find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Identify common web vulnerabilities with an active library of community-powered templates.

Examine cloud environments and infrastructure for misconfigurations and vulnerabilities.

Scan non web services like SSH, FTP, SMB, and more.

Test APIs with an active library of known vulnerabilities and misconfigurations.

Audit server configurations, open ports, and services for security issues.

Integrate into your existing pipelines to minimize issues resurfacing into production.

Read the latest news and updates from the Nuclei team.

Two releases shipped this cycle - v10.4.2 (April 15) and v10.4.3 (May 5) - delivering deep KEV coverage, a major push into AI/LLM attack surface, fresh Perforce visibility, and broad quality improvements across the template library. 🚀 April Stats Release New Templates CVEs Added First-time Contributors v10.4.2 121 61 15 v10.4.3 105 62 12 Total 226 123 27 * 226 new templates shipped across both releases * 123 CVEs covered, including ~10 actively exploited vulnerabilities

At ProjectDiscovery, our greatest strength is our community. Thousands of security researchers, bug bounty hunters, and vulnerability analysts who identify zero‑day vulnerabilities, trending CVEs, and actively exploited vulnerabilities (including those listed in CISA KEV).

Discover the highlights from Nuclei Templates v10.2.1 and v10.2.2 releases: 106 new templates, 57 CVEs covered (including 10 actively exploited KEVs), first-time contributions, a new template bounty program, and key improvements to reduce false positives and negatives.

Extracted Entities

Attack Types (1)

CVEs (1)

Platforms (1)

Tools (1)