8000
Skip to content

Latest commit

 

History

224 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Weekly updated list of missing CVEs in nuclei templates official repository


Note This repository is 100% automated so there can be errors, but in general is pretty accurate. Go to section "How it works" to understand how data is collected.

Stats 📊

CVEs analyzed: 167758

CVEs missing: 66838

Dropdown by vuln type:

Type Count Data
XSS 23447 xss.txt
RCE 3532 rce.txt
SQL Injection 13062 sqli.txt
Local File Inclusion 388 lfi.txt
Server Side Request Forgery 459 ssrf.txt
Prototype Pollution 321 proto-pollution.txt
Request Smuggling 116 req-smuggling.txt
Open Redirect 466 open-redirect.txt
XML External Entity 481 xxe.txt
Path Traversal 3919 path-traversal.txt
Server Side Template Injection 96 ssti.txt
Denial of Service 15977 dos.txt

Dropdown by year:

Year Count Data
1999 40 1999.txt
2000 48 2000.txt
2001 76 2001.txt
2002 159 2002.txt
2003 124 2003.txt
2004 352 2004.txt
2005 719 2005.txt
2006 1494 2006.txt
2007 1594 2007.txt
2008 2545 2008.txt
2009 1255 2009.txt
2010 1188 2010.txt
2011 690 2011.txt
2012 912 2012.txt
2013 906 2013.txt
2014 1542 2014.txt
2015 1942 2015.txt
2016 1860 2016.txt
2017 2856 2017.txt
2018 3347 2018.txt
2019 2653 2019.txt
2020 3557 2020.txt
2021 4087 2021.txt
2022 4803 2022.txt
2023 6517 2023.txt
2024 10465 2024.txt
2025 7811 2025.txt
2026 3296 2026.txt

Why 🤔

  • Bug bounty: the CVE templates in the official nuclei-templates repo are completely useless for bug bounty. This because everyone is using those templates looking for low hanging fruit. Build your own templates for new (and old!) CVEs, scan all the possible targets and don't forget to share them in the official nuclei-templates repo.
  • General Security: Security people can write their own templates for missing CVEs and use them to secure products during pentests, vuln assessments, red team ops and so on... every user will benefit from these actions. If they are very good security people they'll share the templates in official nuclei-templates repo helping the whole infosec community.
  • Stats & Data lover: I love data and statistics and I hope people like me will enjoy.

How it works 🖥️

Automated Logic:

for each cve in trickest/cve:
    if this cve not present in nuclei-templates:
        if it contains one of the words we are looking for:
            if it is a CVE suitable for nuclei:
                print it
<
7654
/pre>
  • Which are the "words we are looking for"? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, SQL injection, Prototype pollution, XML External Entity, Request Smuggling, XXE, Open redirect, Path Traversal, Directory Traversal and Denial of Service.

  • This means the tracked vulnerability types are: XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection and Denial of Service; but new vuln types will be supported.

  • Why there can be errors in categorizing CVEs? Because when grepping for these words there can be false positives, meaning that an XXE vulnerability can be categorized as RCE because e.g. it says "in certain situations can be escalated to rce".

  • Why if I subtract the "CVEs missing" from the "CVEs analyzed" I don't get the exact official nuclei templates count? Because as said before the tracked vuln types are just 10 (the most famous ones), but a lot of other types are reported as well (and they will be supported).

  • What does it mean a CVE is suitable for Nuclei? Basically a remote web or network vulnerability (e.g. a CVE on Android is not suitable).

Contributing 🛠

Just open an issue / pull request.

Thanks 💝

License 📝

This repository is under MIT License.
edoardottt.com to contact me.

About

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.

Topics

Resources

Stars

445 stars

Watchers

11 watching

Forks

Releases

Sponsor this project

Used by

Contributors

Languages

0