ProjectDiscovery Nuclei Templates ReleasesEXPLOIT SOURCEUNKNOWN
Nuclei Templates v10.4.2 – Release Notes
New Templates Added: 121 | CVEs Added: 61 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-21643 ] Fortinet FortiClientEMS 7.4.4 - SQL Injection ( @ritikchaddha ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-35616 ] FortiClient EMS - Authentication Bypass ( @ritikchaddha ) [high] 🔥 (kev) (vKEV) [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE ( @ritikchaddha ) [critical] 🔥 (vKEV) [ CVE-2025-59528 ] Flowise - Remote Code Execution (@xtr0nix) [critical] 🔥 (vKEV) [ CVE-2026-3584 ] WordPress Kali Forms <= 2.4.9 - Remote Code Execution ( @pussycat0x ) [critical] 🔥 (vKEV) [ CVE-2026-4020 ] Gravity SMTP WordPress Plugin - Sensitive Information Exposure ( @theamanrawat ) [high] 🔥 (vKEV) [ CVE-2026-34197 ] Apache ActiveMQ - Remote Code Execution ( @dhiyaneshdk , @horizon3 ) [critical] 🔥 [ CVE-2026-34156 ] NocoBase - VM Sandbox Escape to Remote Code Execution ( @theamanrawat ) [critical] 🔥 [ CVE-2026-20079 ] Cisco Secure Firewall Management Center - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-26980 ] Ghost CMS Content API - SQL Injection ( @domwhewell-sage ) [critical] 🔥 [ CVE-2026-4257 ] WordPress Contact Form by Supsystic - Server-Side Template Injection ( @theamanrawat ) [critical] 🔥 [ CVE-2026-2699 ] Progress ShareFile Storage Zones Controller - Authentication Bypass ( @dhiyaneshdk ) [critical] 🔥 [CVE-2026-33340] LoLLMs WEBUI - Server-Side Request Forgery ( @theamanrawat ) [critical] 🔥 [ CVE-2025-67303 ] ComfyUI-Manager < 3.38 - Configuration Overwrite ( @maciejklimek ) [critical] 🔥 [ CVE-2024-38819 ] Spring Framework Path Traversal in Functional Web Frameworks ( @dhiyaneshdk ) [high] 🔥 What's Changed Bug Fixes Moved CVE-2026-23829 template from incorrect http folder to the network folder (Issue #15633 , PR #15738 ). Fixed CVE-ID mismatches in template metadata (PR #15850 ). Fixed invalid CPE formats across multiple HTTP templates (PR #15751 ). Fixed tag formatting in CVE-2023-38875 , CVE-2025-11307 , CVE-2023-24322 , and CVE-2025-4210 templates (PRs #15897 , #15898 , #15899 , #15900 ). Updated CVE-2023-6825 template to correct detection logic (PR #15877 ). Corrected template author attribution from PentesterTN to 0xBassia (PR #15827 ). False Negatives Fixed false negatives in CVE-2024-8529 (LearnPress SQLi): body matchers were unreliable for blind SQLi responses and a randstr bypass was added to defeat DB query cache (Issue #15768 , PR #15844 ). False Positives Reduced extremely high false positives in credentials-disclosure template caused by over-permissive [\w-]+ value regex with no minimum length enforcement, flagging short UI strings like "ClientSecret":"Client" as credential leaks (Issue #15563 , PR #15845 ). Reduced false positives in the Apache ActiveMQ Artemis Console Default Login template; tightened matcher to require a valid JSON login response with expected artemis username (Issue #15762 , PR #15861 ). Resolved false positives in molgenis-default-login template triggered by JSESSIONID cookies on custom 404 pages (Issue #12603 ). Removed false positive subdomain takeover detection templates for Netlify, Shopify, Azure Azurewebsites, Cloudapp, and Trafficmanager - these services are no longer vulnerable due to enforced TXT verification, deprecation, or claimed namespace blocking (PR #15724 ). Fixed false positive webpack-config detection triggered by SPA catch-all routing (PR #15869 ). Improved CVE-2022-3254 matchers to reduce false positives on HTML error responses (PR #15840 ). Fixed false positives in CVE-2024-52762 (PR #15833 ). Fixed false positives in CVE-2025-49113 (PR #15777 ). Enhancements Refactored matchers in CVE-2024-42009 for improved detection accuracy (PR #15835 ). Added and normalized CWE metadata across HTTP templates (PR #15804 ). Added additional EOL version entries to end-of-life detection templates (PR #15891 ). Updated CVE-2025-30208 detection coverage (PR #15784 ). Templates Added [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal W
CVE-2021-23337CVE-2021-46371CVE-2022-3254CVE-2022-41678CVE-2023-24322CVE-2023-38875CVE-2023-40924CVE-2023-49293CVE-2023-6592CVE-2023-6750CVE-2023-6825CVE-2023-7165CVE-2024-28752CVE-2024-38819CVE-2024-42009CVE-2024-49357CVE-2024-52762CVE-2024-8252CVE-2024-8529CVE-2025-11307CVE-2025-12536CVE-2025-13652CVE-2025-14124CVE-2025-14340CVE-2025-2221CVE-2025-2558CVE-2025-30208CVE-2025-32614CVE-2025-4210CVE-2025-49113CVE-2025-50578CVE-2025-5350CVE-2025-53533CVE-2025-54597CVE-2025-55150CVE-2025-59528CVE-2025-64500CVE-2025-67303CVE-2026-20079CVE-2026-21643CVE-2026-23829CVE-2026-2416CVE-2026-25616CVE-2026-26980CVE-2026-2699CVE-2026-28358CVE-2026-28414CVE-2026-29014CVE-2026-29066CVE-2026-29183CVE-2026-30824CVE-2026-31807CVE-2026-31809CVE-2026-33340CVE-2026-33478CVE-2026-3396CVE-2026-34156CVE-2026-34197CVE-2026-34453CVE-2026-34605CVE-2026-34885CVE-2026-35616CVE-2026-3584CVE-2026-39364CVE-2026-39365CVE-2026-39987CVE-2026-4020CVE-2026-4106CVE-2026-4257CVE-2026-5615CVE-2026-6118CVE-2026-6203