
주간 업데이트되는 nuclei templates 공식 저장소에서 누락된 CVE 목록입니다. 주로 버그 바운티를 위해 제작되었지만, 침투 테스트 및 취약점 평가에도 유용합니다.
참고 이 저장소는 100% 자동화되어 있으므로 오류가 있을 수 있지만, 일반적으로 매우 정확합니다. 데이터가 어떻게 수집되는지 이해하려면 "작동 방식" 섹션으로 이동하세요.
분석된 CVE: 164807
누락된 CVE: 65840
취약점 유형별 분류:
| 유형 | 개수 | 데이터 |
|---|---|---|
| XSS | 23215 | xss.txt |
| RCE | 3426 | rce.txt |
| SQL Injection | 12803 | sqli.txt |
| Local File Inclusion | 384 | lfi.txt |
| Server Side Request Forgery | 433 | ssrf.txt |
| Prototype Pollution | 313 | proto-pollution.txt |
| Request Smuggling | 114 | req-smuggling.txt |
| Open Redirect | 456 | open-redirect.txt |
| XML External Entity | 478 | xxe.txt |
| Path Traversal | 3848 | path-traversal.txt |
| Server Side Template Injection | 93 | ssti.txt |
| Denial of Service | 15792 | dos.txt |
연도별 분류:
자동화 로직:
for each cve in trickest/cve:
if this cve not present in nuclei-templates:
if it contains one of the words we are looking for:
if it is a CVE suitable for nuclei:
print it
우리가 찾는 "단어"는 무엇인가요? reflected, rce, local file inclusion, server side request forgery, ssrf, remote code execution, remote command execution, command injection, code injection, ssti, template injection, lfi, xss, Cross-Site Scripting, Cross Site Scripting, , , , , , , , 및 입니다.
이 저장소는 MIT License를 따릅니다.
edoardottt.com으로 연락해 주세요.
| 연도 | 개수 | 데이터 |
|---|
| 1999 | 40 | 1999.txt |
| 2000 | 48 | 2000.txt |
| 2001 | 76 | 2001.txt |
| 2002 | 159 | 2002.txt |
| 2003 | 121 | 2003.txt |
| 2004 | 333 | 2004.txt |
| 2005 | 709 | 2005.txt |
| 2006 | 1488 | 2006.txt |
| 2007 | 1582 | 2007.txt |
| 2008 | 2536 | 2008.txt |
| 2009 | 1249 | 2009.txt |
| 2010 | 1185 | 2010.txt |
| 2011 | 685 | 2011.txt |
| 2012 | 909 | 2012.txt |
| 2013 | 902 | 2013.txt |
| 2014 | 1541 | 2014.txt |
| 2015 | 1942 | 2015.txt |
| 2016 | 1854 | 2016.txt |
| 2017 | 2848 | 2017.txt |
| 2018 | 3345 | 2018.txt |
| 2019 | 2652 | 2019.txt |
| 2020 | 3540 | 2020.txt |
| 2021 | 4072 | 2021.txt |
| 2022 | 4793 | 2022.txt |
| 2023 | 6510 | 2023.txt |
| 2024 | 10451 | 2024.txt |
| 2025 | 7719 | 2025.txt |
| 2026 | 2551 | 2026.txt |
SQL injectionPrototype pollutionXML External EntityRequest SmugglingXXEOpen redirectPath TraversalDirectory TraversalDenial of Service즉, 추적되는 취약점 유형은 XSS, RCE, SQL injection, Local File Inclusion, Server Side Request Forgery, Prototype Pollution, Request Smuggling, Open Redirect, XML Enternal Entity, Path Traversal, Server Side Template Injection 및 Denial of Service입니다. 그러나 새로운 취약점 유형도 지원될 예정입니다.
CVE 분류에 오류가 있을 수 있는 이유는 무엇인가요? 이러한 단어를 grep할 때 오탐이 발생할 수 있기 때문입니다. 예를 들어 XXE 취약점이 "특정 상황에서 rce로 확대될 수 있다"고 명시되어 있어 RCE로 분류될 수 있습니다.
"분석된 CVE"에서 "누락된 CVE"를 빼면 정확한 공식 nuclei 템플릿 개수가 나오지 않는 이유는 무엇인가요? 앞서 말했듯이 추적되는 취약점 유형은 10개(가장 유명한 것들)뿐이지만, 다른 많은 유형도 함께 보고되기 때문입니다(그리고 이들도 지원될 예정입니다).
CVE가 Nuclei에 적합하다는 것은 무엇을 의미하나요? 기본적으로 원격 웹 또는 네트워크 취약점을 의미합니다(예: Android의 CVE는 적합하지 않습니다).