
न्यूक्ली टेम्प्लेट्स आधिकारिक रिपॉजिटरी में अनुपलब्ध CVEs की साप्ताहिक अद्यतन सूची। मुख्य रूप से बग बाउंटी के लिए निर्मित, लेकिन पेनेट्रेशन परीक्षण और भेद्यता आकलन के लिए भी उपयोगी।
नोट यह रिपॉज़िटरी 100% स्वचालित है इसलिए इसमें त्रुटियाँ हो सकती हैं, लेकिन सामान्यतः यह काफी सटीक है। यह समझने के लिए कि डेटा कैसे एकत्र किया जाता है, "यह कैसे काम करता है" अनुभाग पर जाएँ।
विश्लेषित CVEs: 164807
अनुपलब्ध CVEs: 65840
भेद्यता प्रकार के अनुसार ड्रॉपडाउन:
| प्रकार | गिनती | डेटा |
|---|---|---|
| XSS | 23215 | xss.txt |
| RCE | 3426 | rce.txt |
| SQL Injection | 12803 | sqli.txt |
| Local File Inclusion | 384 | lfi.txt |
| Server Side Request Forgery | 433 | ssrf.txt |
| Prototype Pollution | 313 | proto-pollution.txt |
| Request Smuggling | 114 | req-smuggling.txt |
| Open Redirect | 456 | open-redirect.txt |
| XML External Entity | 478 | xxe.txt |
| Path Traversal | 3848 | path-traversal.txt |
| Server Side Template Injection | 93 | ssti.txt |
| Denial of Service | 15792 | dos.txt |
वर्ष के अनुसार ड्रॉपडाउन:
स्वचालित लॉजिक:
for each cve in trickest/cve:
if this cve not present in nuclei-templates:
if it contains one of the words we are looking for:
if it is a CVE suitable for nuclei:
print it
हम किन "शब्दों की तलाश" में हैं? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, , , , , , , , और ।
बस एक issue / pull request खोलें।
यह रिपॉज़िटरी MIT License के अंतर्गत है।
मुझसे संपर्क करने के लिए edoardottt.com पर जाएँ।
| वर्ष | गिनती | डेटा |
|---|
| 1999 | 40 | 1999.txt |
| 2000 | 48 | 2000.txt |
| 2001 | 76 | 2001.txt |
| 2002 | 159 | 2002.txt |
| 2003 | 121 | 2003.txt |
| 2004 | 333 | 2004.txt |
| 2005 | 709 | 2005.txt |
| 2006 | 1488 | 2006.txt |
| 2007 | 1582 | 2007.txt |
| 2008 | 2536 | 2008.txt |
| 2009 | 1249 | 2009.txt |
| 2010 | 1185 | 2010.txt |
| 2011 | 685 | 2011.txt |
| 2012 | 909 | 2012.txt |
| 2013 | 902 | 2013.txt |
| 2014 | 1541 | 2014.txt |
| 2015 | 1942 | 2015.txt |
| 2016 | 1854 | 2016.txt |
| 2017 | 2848 | 2017.txt |
| 2018 | 3345 | 2018.txt |
| 2019 | 2652 | 2019.txt |
| 2020 | 3540 | 2020.txt |
| 2021 | 4072 | 2021.txt |
| 2022 | 4793 | 2022.txt |
| 2023 | 6510 | 2023.txt |
| 2024 | 10451 | 2024.txt |
| 2025 | 7719 | 2025.txt |
| 2026 | 2551 | 2026.txt |
SQL injectionPrototype pollutionXML External EntityRequest SmugglingXXEOpen redirectPath TraversalDirectory TraversalDenial of Serviceइसका अर्थ है कि ट्रैक किए जाने वाले भेद्यता प्रकार हैं: XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection और Denial of Service; लेकिन नए भेद्यता प्रकारों का भी समर्थन किया जाएगा।
CVEs को वर्गीकृत करने में त्रुटियाँ क्यों हो सकती हैं? क्योंकि इन शब्दों को खोजते समय गलत सकारात्मक परिणाम (false positives) आ सकते हैं, जिसका अर्थ है कि एक XXE भेद्यता को RCE के रूप में वर्गीकृत किया जा सकता है, क्योंकि उदाहरण के लिए उसमें लिखा होता है "कुछ स्थितियों में इसे rce तक बढ़ाया जा सकता है"।
यदि मैं "CVEs analyzed" में से "CVEs missing" घटाऊँ, तो मुझे आधिकारिक nuclei टेम्पलेट्स की सटीक संख्या क्यों नहीं मिलती? क्योंकि जैसा पहले कहा गया है, ट्रैक किए जाने वाले भेद्यता प्रकार केवल 10 हैं (सबसे प्रसिद्ध), लेकिन कई अन्य प्रकार भी रिपोर्ट किए जाते हैं (और उनका भी समर्थन किया जाएगा)।
किसी CVE के Nuclei के लिए उपयुक्त होने का क्या अर्थ है? मूल रूप से एक रिमोट वेब या नेटवर्क भेद्यता (जैसे, Android पर कोई CVE उपयुक्त नहीं है)।