Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

projectdiscovery — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting projectdiscovery. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Projectdiscovery operates as an open-source attack surface management platform, enabling organizations to identify and analyze internet-facing assets. The project has contributed to 7 CVE disclosures, primarily focusing on remote code execution, cross-site scripting, and privilege escalation vulnerabilities in web applications and network services. Its tools facilitate automated discovery of misconfigurations and exposed services across various infrastructure components. While no major security incidents have been publicly attributed to the project, its extensive use in security research has led to the identification of vulnerabilities in numerous third-party systems, highlighting both its effectiveness and the critical need for continuous attack surface monitoring in modern environments.

Top products by projectdiscovery: nuclei interactsh
CVE ID Title CVSS Severity Published
CVE-2026-76805 Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode — nuclei CWE-200 5.3 Medium 2026-09-22
CVE-2026-76802 Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass — nuclei CWE-78 4.7 Medium 2026-09-22
CVE-2026-76804 Nuclei: Local File Read via Workflow File-Protocol Gate Bypass — nuclei CWE-284 5.5 Medium 2026-09-22
CVE-2026-76803 Nuclei: Local File Read via MySQL Client Sandbox Bypass — nuclei CWE-284 5.3 Medium 2026-09-22
CVE-2026-92718 Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache — nuclei CWE-347 7.3 High 2026-09-16
CVE-2026-41645 Nuclei: Environment variable disclosure via Response-Derived DSL Expressions — nuclei CWE-94 5.3 Medium 2026-05-08
CVE-2026-41646 Nuclei: Local File Read via require() Module Loader Bypass — nuclei CWE-284 5.5 Medium 2026-05-08
CVE-2026-41282 Nuclei 安全漏洞 — Nuclei CWE-94 4.0 Medium 2026-04-20
CVE-2024-43405 Nuclei Template Signature Verification Bypass — nuclei CWE-78 7.4 High 2024-09-04
CVE-2024-40641 Unsigned code template execution through workflows in projectdiscovery/nuclei — nuclei CWE-78 7.4 High 2024-07-17
CVE-2024-5262 ProjectDiscovery Interactsh - Files or Directories Accessible to External Parties — Interactsh CWE-552 9.1AI Critical AI 2024-06-05
CVE-2024-27920 Unsigned code template execution through workflows in projectdiscovery/nuclei — nuclei CWE-78 7.4 High 2024-03-15
CVE-2023-37896 Nuclei Path Traversal vulnerability — nuclei CWE-22 7.5 High 2023-08-04
CVE-2023-36474 Interactsh server settings make users vulnerable to Subdomain Takeover — interactsh CWE-79 8.2 High 2023-06-28

This page lists every published CVE security advisory associated with projectdiscovery. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.