Skip to content

Releases: projectdiscovery/nuclei-templates

v9.6.3

11 Sep 14:52
Compare
Choose a tag to compare

🔥 Highlight of this release:

✅ [CVE-2023-39361] Cacti 1.2.24 - SQL Injection (@ritikchaddha) [critical] 🔥
✅ [CVE-2023-36844] Juniper Devices - Remote Code Execution (@princechaddha,@ritikchaddha) [medium] 🔥
✅ [CVE-2023-34124] SonicWall GMS and Analytics Web Services - Shell Injection (@iamnoooob,@rootxharsh,@pdresearch) [critical] 🔥
✅ [CVE-2023-32563] Ivanti Avalanche - Remote Code Execution (@princechaddha) [critical] 🔥
✅ [CVE-2023-26469] Jorani 1.0.0 - Remote Code Execution (@pussycat0x) [critical] 🔥
✅ [CVE-2023-20073] Cisco VPN Routers - Unauthenticated Arbitrary File Upload (@princechaddha,@ritikchaddha) [critical] 🔥
✅ [CVE-2023-4634] Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion (@Pepitoh,@ritikchaddha) [critical] 🔥

What's Changed

New Templates Added: 54

New CVEs Added: 21

First-time contributions: 6


New Contributors

Full Changelog: v9.6.2...v9.6.3

v9.6.2

24 Aug 18:03
Compare
Choose a tag to compare

🔥 Highlight of this release:

[CVE-2023-38035] Ivanti Sentry - Authentication Bypass (@dhiyaneshdk,@iamnoooob,@rootxharsh) [critical] 🔥
[CVE-2022-47615] LearnPress Plugin < 4.2.0 - Local File Inclusion (@dhiyaneshdk) [critical] 🔥
[CVE-2022-46463] Harbor <=2.5.3 - Unauthorized Access (@arm!tage) [high] 🔥
[CVE-2022-39986] RaspAP 2.8.7 - Unauthenticated Command Injection (@dhiyaneshdk) [critical] 🔥
[CVE-2019-17662] ThinVNC 1.0b1 - Authentication Bypass (@dhiyaneshdk) [critical] 🔥

What's Changed

New Templates Added : 60

New CVEs Added: 15

First-time contributions: 7


New Contributors

Full Changelog: v9.6.1...v9.6.2

v9.6.1 [Malware Detection Templates]

13 Aug 00:29
Compare
Choose a tag to compare

What's Changed

This release introduces an extensive set of malware detection templates. These templates have been curated to facilitate the automated identification and categorization of various malware strains using file protocol.

New Templates Added: 198

New CVEs Added: 25

First-time contributions: 6

Read more

v9.6.0

28 Jul 21:47
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v9.5.8...v9.5.9

v9.5.8 [JARM-based C2 Server Detection Templates]

18 Jul 09:58
Compare
Choose a tag to compare

🔥 Highlight of this release:

This release adds a collection of C2 server detection templates. These templates can be used for automating the identification and classification of various C2 servers based on their JARM fingerprints.

What's Changed

New Templates Added : 113

New CVEs Added: 9

New Contributors

Full Changelog: v9.5.7...v9.5.8

v9.5.7

12 Jul 22:40
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v9.5.6...v9.5.7

v9.5.6

09 Jul 09:53
Compare
Choose a tag to compare

What's Changed

Full Changelog: v9.5.5...v9.5.6

v9.5.5

08 Jul 07:13
Compare
Choose a tag to compare

What's Changed

🔥 Highlights of this release:

[CVE-2023-30777] Advanced Custom Fields < 6.1.6 - Cross-Site Scripting (@r3y3r53) [medium] 🔥
[CVE-2023-28121] WooCommerce Payments - Unauthorized Admin Access (@dhiyaneshdk) [critical] 🔥
[CVE-2023-2822] Ellucian Ethos Identity CAS - Cross-Site Scripting (@guax1) [medium] 🔥
[CVE-2023-0297] PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE) (@MrHarshvardhan,@dhiyaneshdk) [critical] 🔥
[CVE-2022-4295] Show all comments < 7.0.1 - Cross-Site Scripting (@r3y3r53) [medium] 🔥


New Templates Added: 90

New CVEs Added: 41

New Contributors

Full Changelog: v9.5.4...v9.5.5

v9.5.4

02 Jul 17:57
Compare
Choose a tag to compare

What's Changed

New Templates Added : 51

New CVEs Added: 26

New Contributors

Full Changelog: v9.5.3...v9.5.4

v9.5.3

21 Jun 04:24
Compare
Choose a tag to compare

🔥 Highlights of this release:

✅ [CVE-2023-34362] MOVEit Transfer - Remote Code Execution (@princechaddha,@rootxharsh,@ritikchaddha,@pdresearch) [critical]
✅ [CVE-2023-34960] Chamilo Command Injection (@dhiyaneshdk) [high]
✅ [CVE-2023-33246] RocketMQ <= 5.1.0 - Remote Code Execution (@iamnoooob,@rootxharsh,@pdresearch) [critical]
✅ [CVE-2023-25157] GeoServer OGC Filter - SQL Injection (@ritikchaddha,@dhiyaneshdk,@iamnoooob,@rootxharsh) [critical]
✅ [CVE-2023-23333] SolarView Compact 6.00 - OS Command Injection (@Mr-xn) [critical]
✅ [CVE-2023-20887] VMware VRealize Network Insight - Remote Code Execution (@sinsinology) [critical]
✅ [CVE-2022-23544] MeterSphere < 2.5.0 SSRF (@j4vaovo) [medium]
✅ [CVE-2022-24706] CouchDB Erlang Distribution - Remote Command Execution (@Mzack9999,@pussycat0x) [critical]
✅ [CVE-2017-12617] Apache Tomcat - Remote Code Execution (@pussycat0x) [high]
✅ [CVE-2016-6195] vBulletin <= 4.2.3 - SQL Injection (@mastercho) [high]

What's Changed

New Templates Added: 62

New CVEs Added: 28

New Contributors

Full Changelog: v9.5.2...v9.5.3