
न्यूक्ली टेम्प्लेट्स आधिकारिक रिपॉजिटरी में अनुपलब्ध CVEs की साप्ताहिक अद्यतन सूची। मुख्य रूप से बग बाउंटी के लिए निर्मित, लेकिन पेनेट्रेशन परीक्षण और भेद्यता आकलन के लिए भी उपयोगी।
नोट यह रिपॉजिटरी 100% स्वचालित है, इसलिए इसमें त्रुटियाँ हो सकती हैं, लेकिन सामान्यतः यह काफी सटीक है। डेटा कैसे एकत्र किया जाता है, यह समझने के लिए "यह कैसे काम करता है" अनुभाग पर जाएँ।
विश्लेषित CVE: 170230
अनुपलब्ध CVE: 67954
भेद्यता प्रकार के अनुसार ड्रॉपडाउन:
| प्रकार | संख्या | डेटा |
|---|
| XSS | 23659 | xss.txt |
| RCE | 3603 | rce.txt |
| SQL Injection | 13533 | sqli.txt |
| Local File Inclusion | 391 | lfi.txt |
| Server Side Request Forgery | 477 | ssrf.txt |
| Prototype Pollution | 321 | proto-pollution.txt |
| Request Smuggling | 116 | req-smuggling.txt |
| Open Redirect | 469 | open-redirect.txt |
| XML External Entity | 482 | xxe.txt |
| Path Traversal | 4068 | path-traversal.txt |
| Server Side Template Injection | 99 | ssti.txt |
| Denial of Service | 16125 | dos.txt |
वर्ष के अनुसार ड्रॉपडाउन:
स्वचालित तर्क:
for each cve in trickest/cve:
if this cve not present in nuclei-templates:
if it contains one of the words we are looking for:
if it is a CVE suitable for nuclei:
print it
"हम जिन शब्दों की तलाश कर रहे हैं" वे कौन से हैं? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, SQL injection, Prototype pollution, XML External Entity, Request Smuggling, XXE, Open redirect, Path Traversal, Directory Traversal और Denial of Service।
इसका मतलब है कि ट्रैक किए जाने वाले भेद्यता प्रकार हैं: XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection और Denial of Service; लेकिन नए भेद्यता प्रकार भी समर्थित होंगे।
CVE के वर्गीकरण में त्रुटियाँ क्यों हो सकती हैं? क्योंकि इन शब्दों को grep करते समय गलत सकारात्मक परिणाम हो सकते हैं, जिसका अर्थ है कि एक XXE भेद्यता को RCE के रूप में वर्गीकृत किया जा सकता है क्योंकि उदाहरण के लिए इसमें लिखा होता है "कुछ स्थितियों में इसे rce तक बढ़ाया जा सकता है"।
यदि मैं "अनुपलब्ध CVE" को "विश्लेषित CVE" से घटाऊँ तो मुझे सटीक आधिकारिक nuclei टेम्पलेट्स संख्या क्यों नहीं मिलती? क्योंकि जैसा कि पहले कहा गया है, ट्रैक किए जाने वाले भेद्यता प्रकार केवल 10 (सबसे प्रसिद्ध) हैं, लेकिन कई अन्य प्रकार भी रिपोर्ट किए जाते हैं (और वे भी समर्थित होंगे)।
इसका क्या अर्थ है कि एक CVE Nuclei के लिए उपयुक्त है? मूल रूप से एक रिमोट वेब या नेटवर्क भेद्यता (उदाहरण के लिए Android पर एक CVE उपयुक्त नहीं है)।
बस एक issue / pull request खोलें।
यह रिपॉजिटरी MIT License के अंतर्गत है।
मुझसे संपर्क करने के लिए edoardottt.com।
| 2013 | 931 | 2013.txt |
| 2014 | 1570 | 2014.txt |
| 2015 | 1945 | 2015.txt |
| 2016 | 1870 | 2016.txt |
| 2017 | 2857 | 2017.txt |
| 2018 | 3354 | 2018.txt |
| 2019 | 2653 | 2019.txt |
| 2020 | 3560 | 2020.txt |
| 2021 | 4090 | 2021.txt |
| 2022 | 4804 | 2022.txt |
| 2023 | 6518 | 2023.txt |
| 2024 | 10469 | 2024.txt |
| 2025 | 7829 | 2025.txt |
| 2026 | 3677 | 2026.txt |