ProjectDiscovery Nuclei Templates ReleasesEXPLOIT SOURCEUNKNOWN
Nuclei Templates v10.4.6 - Release Notes
New Templates Added: 74 | CVEs Added: 23 | First-time contributions: 6 🔥 Release Highlights 🔥 [ CVE-2026-52815 ] Gogs < 0.14.3 - Unauth Organization Teams Disclosure (@0x_Akoko) [low] 🔥 [ CVE-2026-50229 ] Apache Tomcat - Cross-Site Scripting (@yshahinzadeh, @AmirMSafari ) [medium] 🔥 [ CVE-2026-48611 ] phpBB < 3.3.17 - Auth Bypass ( @aikido , @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-48313 ] ColdFusion - Path Traversal ( @watchtowr , @dhiyaneshdk ) [high] 🔥 [ CVE-2026-48282 ] Adobe ColdFusion - RDS Arbitrary File Write ( @watchtowr , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-44381] MISP < 2.5.37 - SQL Injection ( @malcha ) [medium] 🔥 [CVE-2026-28496] FOSSBilling - Server-Side Template Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-24207 ] NVIDIA Triton Inference Server <= 26.02 - Auth Bypass ( @VixianSchool ) [critical] 🔥 [ CVE-2026-22778 ] vLLM 0.8.3 - 0.14.0 - Information Disclosure ( @kenlacroix ) [critical] 🔥 [ CVE-2026-13731 ] WPBot <= 8.4.9 - Cross-Site Scripting (@0x_Akoko) [high] (vKEV) 🔥 [ CVE-2026-8386 ] WP Go Maps < 10.0.10 - Unauth Marker Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8383 ] LearnPress < 4.3.7 - Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8037 ] Progress ADC LoadMaster - Command Injection ( @watchtowr , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-3326 ] XStore Theme < 9.7.3 - SQL Injection ( @VixianSchool ) [high] 🔥 [ CVE-2026-1890 ] LeadConnector < 3.0.22 - Unauth Arbitrary Data Write (@0x_Akoko) [medium] (vKEV) 🔥 [ CVE-2025-29635 ] D-Link DIR-823X set_prohibiting - Command Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 What's Changed Bug Fixes Fixed invalid matcher type in CVE-2025-29635 (PR #16506 ). Corrected incorrect delay seconds in the time-based SQL injection check (PR #16469 ). Fixed typo in tags from 'okiko' to 'okiok' (PR #16425 ). Corrected severity and description in concrete5-installer.yaml (PR #16523 ). Updated GitHub Pages takeover detection templates to reflect the new GitHub policy (Issue #10514 ). Fixed checksum generation ordering so it runs after template signing completes (PR #16450 ). Removed duplicate and obsolete templates: Tomcat exposed-panels duplicates (PR #16530 ), mikrotik-routeros-old.yaml (PR #16527 ), and 3dprint-arbitrary-file-upload.yaml (PR #16426 ). Corrected template names and file paths across a set of templates — nuuo-network-login (PR #16547 ), fuji-xerox-internet-service (PR #16546 ), trino-unauth-cluster (PR #16560 ), echo-detect (PR #16559 ), XOOPS installer (PR #16531 ), osticket-installer (PR #16529 ), zoneminder-system-log (PR #16498 ), unauth-opcache-control-panel (PR #16424 ), fortiadc-panel (PR #16525 ), Checkmarx panel (PR #16519 ), Cisco TelePresence MCU / ServiceGrid / ACE 4710 panels (PRs #16522 , #16521 , #16520 ), Avaya Aura System Manager and Communication Manager panels (PRs #16518 , #16517 ), joomla-com-fabrik-lfi (PR #16549 ), CVE-2016-9299 (PR #16548 ), and CVE-2025-47188 (PR #16433 ). False Negatives Fixed regex in CVE-2026-1731 that failed on targets returning company instead of default_company (PR #16545 , Issue #16544 ). Extended the Spring Boot heap dump template to cover additional BBO endpoints, catching instances previously missed (PR #16503 , Issue #11653 ). Added more selectors to dkim-record-detect.yaml to reduce missed records (PR #16535 ). Added additional Keycloak admin panel paths (PR #16495 , Issue #16376 ). Added another Spring Boot Actuator HTTP path (PR #16571 ). False Positives Reduced false positives and improved accuracy in the following templates: CVE-2024-37881 — excluded multiple WordPress endpoints and generic redirects (PRs #16494 , #16504 , Issue #16423 ) CVE-2024-34351 — corrected wrong detection (PR #16500 , Issue #11641 ) Time-based SQL injection detection (PR #16510 ) Casbin MCP Gateway default login (PR #16477 ) dns/caa — now matches only the ANSWER section (PR #16453 ) apache-mod-negotiation-listing.yaml - incorrect severity (Issue #16
CVE-2010-4282CVE-2016-9299CVE-2019-5544CVE-2024-34351CVE-2024-37881CVE-2025-29635CVE-2025-47188CVE-2026-10823CVE-2026-13731CVE-2026-1731CVE-2026-1890CVE-2026-22778CVE-2026-24207CVE-2026-28496CVE-2026-30958CVE-2026-3326CVE-2026-34413CVE-2026-44381CVE-2026-46339CVE-2026-48282CVE-2026-48313CVE-2026-48611CVE-2026-50229CVE-2026-50751CVE-2026-52774CVE-2026-52815CVE-2026-56782CVE-2026-59801CVE-2026-8037CVE-2026-8383CVE-2026-8386