Back to updates
New releaseSep 1, 2026

missing-cve-nuclei-templates v2026-08-10

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.

Share

Weekly updated list of missing CVEs in nuclei templates official repository


Note This repository is 100% automated so there can be errors, but in general is pretty accurate. Go to section "How it works" to understand how data is collected.

Stats 📊

CVEs analyzed: 167758

CVEs missing: 66838

Dropdown by vuln type:

TypeCountData
XSS23447xss.txt
RCE3532rce.txt
SQL Injection13062sqli.txt
Local File Inclusion388lfi.txt
Server Side Request Forgery459ssrf.txt
Prototype Pollution321proto-pollution.txt
Request Smuggling116req-smuggling.txt
Open Redirect466open-redirect.txt
XML External Entity481xxe.txt
Path Traversal3919path-traversal.txt
Server Side Template Injection96ssti.txt
Denial of Service15977dos.txt

Dropdown by year:

YearCountData
1999401999.txt
2000482000.txt
2001762001.txt
20021592002.txt
20031242003.txt
20043522004.txt
20057192005.txt
200614942006.txt
200715942007.txt
200825452008.txt
200912552009.txt
201011882010.txt
20116902011.txt
20129122012.txt
20139062013.txt
201415422014.txt
201519422015.txt
201618602016.txt
201728562017.txt
201833472018.txt
201926532019.txt
202035572020.txt
202140872021.txt
202248032022.txt
202365172023.txt
2024104652024.txt
202578112025.txt
202632962026.txt

Why 🤔

  • Bug bounty: the CVE templates in the official nuclei-templates repo are completely useless for bug bounty. This because everyone is using those templates looking for low hanging fruit. Build your own templates for new (and old!) CVEs, scan all the possible targets and don't forget to share them in the official nuclei-templates repo.
  • General Security: Security people can write their own templates for missing CVEs and use them to secure products during pentests, vuln assessments, red team ops and so on... every user will benefit from these actions. If they are very good security people they'll share the templates in official nuclei-templates repo helping the whole infosec community.
  • Stats & Data lover: I love data and statistics and I hope people like me will enjoy.

How it works 🖥️

Automated Logic:

for each cve in trickest/cve:
    if this cve not present in nuclei-templates:
        if it contains one of the words we are looking for:
            if it is a CVE suitable for nuclei:
                print it
  • Which are the "words we are looking for"? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, SQL injection, Prototype pollution, XML External Entity, Request Smuggling, XXE, Open redirect, Path Traversal, Directory Traversal and Denial of Service.

  • This means the tracked vulnerability types are: XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection and Denial of Service; but new vuln types will be supported.

  • Why there can be errors in categorizing CVEs? Because when grepping for these words there can be false positives, meaning that an XXE vulnerability can be categorized as RCE because e.g. it says "in certain situations can be escalated to rce".

  • Why if I subtract the "CVEs missing" from the "CVEs analyzed" I don't get the exact official nuclei templates count? Because as said before the tracked vuln types are just 10 (the most famous ones), but a lot of other types are reported as well (and they will be supported).

  • What does it mean a CVE is suitable for Nuclei? Basically a remote web or network vulnerability (e.g. a CVE on Android is not suitable).

Contributing 🛠

Just open an issue / pull request.

Thanks 💝

License 📝

This repository is under MIT License.
edoardottt.com to contact me.

Categories