
Elenco aggiornato settimanalmente delle CVE mancanti nel repository ufficiale dei template nuclei. Realizzato principalmente per il bug bounty, ma utile anche per test di penetrazione e valutazioni delle vulnerabilità.
Nota Questo repository è automatizzato al 100%, quindi possono esserci errori, ma in generale è piuttosto accurato. Vai alla sezione "Come funziona" per capire come vengono raccolti i dati.
CVE analizzate: 174067
CVE mancanti: 68723
Menu a tendina per tipo di vulnerabilità:
| Tipo | Conteggio | Dati |
|---|---|---|
| XSS | 23811 | xss.txt |
| RCE | 3669 | rce.txt |
| SQL Injection | 13683 | sqli.txt |
| Local File Inclusion | 392 | lfi.txt |
| Server Side Request Forgery | 504 | ssrf.txt |
| Prototype Pollution | 324 | proto-pollution.txt |
| Request Smuggling | 121 | req-smuggling.txt |
| Open Redirect | 478 | open-redirect.txt |
| XML External Entity | 484 | xxe.txt |
| Path Traversal | 4126 | path-traversal.txt |
| Server Side Template Injection | 102 | ssti.txt |
| Denial of Service | 16354 | dos.txt |
Menu a tendina per anno:
| Anno | Conteggio | Dati |
|---|---|---|
| 1999 | 40 | 1999.txt |
| 2000 | 48 | 2000.txt |
| 2001 | 76 | 2001.txt |
| 2002 | 160 | 2002.txt |
| 2003 | 125 | 2003.txt |
| 2004 | 355 | 2004.txt |
| 2005 | 721 | 2005.txt |
| 2006 | 1505 | 2006.txt |
| 2007 | 1597 | 2007.txt |
| 2008 | 2551 | 2008.txt |
| 2009 | 1544 | 2009.txt |
| 2010 | 1369 | 2010.txt |
| 2011 | 762 | 2011.txt |
| 2012 | 984 | 2012.txt |
| 2013 | 934 | 2013.txt |
| 2014 | 1572 | 2014.txt |
| 2015 | 1947 | 2015.txt |
| 2016 | 1877 | 2016.txt |
| 2017 | 2861 | 2017.txt |
| 2018 | 3358 | 2018.txt |
| 2019 | 2658 | 2019.txt |
| 2020 | 3561 | 2020.txt |
| 2021 | 4093 | 2021.txt |
| 2022 | 4804 | 2022.txt |
| 2023 | 6524 | 2023.txt |
| 2024 | 10474 | 2024.txt |
| 2025 | 7842 | 2025.txt |
| 2026 | 4381 | 2026.txt |
Logica automatizzata:
for each cve in trickest/cve:
if this cve not present in nuclei-templates:
if it contains one of the words we are looking for:
if it is a CVE suitable for nuclei:
print it
Quali sono le "parole che stiamo cercando"? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, SQL injection, Prototype pollution, XML External Entity, Request Smuggling, XXE, Open redirect, Path Traversal, Directory Traversal e Denial of Service.
Questo significa che i tipi di vulnerabilità monitorati sono: XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection e Denial of Service; ma verranno supportati nuovi tipi di vulnerabilità.
Perché possono esserci errori nella categorizzazione delle CVE? Perché quando si fa grep di queste parole possono esserci falsi positivi, nel senso che una vulnerabilità XXE può essere categorizzata come RCE perché ad esempio dice "in determinate situazioni può essere escalata a rce".