Filtered by vendor Projectdiscovery
Subscribe
Total
5 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27920 | 1 Projectdiscovery | 1 Nuclei | 2025-12-05 | N/A | 7.4 HIGH |
|
projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates through workflows. This vulnerability specifically affects users utilizing custom workflows, potentially allowing the execution of malicious code on the user's system. This advisory outlines the impacted users, provides details on the security patch, and suggests mitigation strateg ...
Show More |
|||||
| CVE-2024-5262 | 1 Projectdiscovery | 1 Interactsh | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.
|
|||||
| CVE-2023-37896 | 1 Projectdiscovery | 1 Nuclei | 2024-11-21 | N/A | 7.5 HIGH |
|
Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The problem was related to sanitization issues with payload loading in sandbox mode. There was a potential risk with payloads loading in sandbox mode. The issue occurred due to relative paths not being converted to absolute paths before doing the check for `sandbox` flag allowing arbitrary ...
Show More |
|||||
| CVE-2023-36474 | 1 Projectdiscovery | 1 Interactsh | 2024-11-21 | N/A | 8.2 HIGH |
|
Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as default, which intended to used for hosting interactsh web client using GitHub pages. This is a security issue with a self-hosted interactsh server in which the user may not have config ...
Show More |
|||||
| CVE-2024-43405 | 1 Projectdiscovery | 1 Nuclei | 2024-10-01 | N/A | 7.8 HIGH |
|
Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature check and possibly execute malicious code via custom code template. The vulnerability is present in the template signature verification process, specifically in the `signer` package. The vulnerability stems from a discrepancy between how the signature verification ...
Show More |
|||||