Finding security vulnerabilities shouldn’t require reinventing detection logic every time. This repository is the ammunition depot for Nuclei scanner - nearly 12,000 community-curated templates that detect everything from forgotten admin panels to zero-day exploits. With 1,496 templates covering CISA’s Known Exploited Vulnerabilities catalog, you’re scanning for threats that attackers are actively using in the wild.

What sets this apart is the sheer breadth and quality of community contributions. Security researchers worldwide contribute templates for CVEs, misconfigurations, exposed services, and custom attack patterns. The templates are YAML-based, making them readable and easy to customize. Whether you’re hunting for Log4j vulnerabilities, misconfigured cloud services, or that obscure CMS exploit from last week, there’s likely a template ready to go.

Perfect for bug bounty hunters, penetration testers, and security teams who need comprehensive vulnerability detection without building everything from scratch. The active community means new threats get template coverage fast, and the standardized format means you can contribute your own discoveries back to help others.


Stars: 11935
💻 Language: JavaScript
🔗 Repository: projectdiscovery/nuclei-templates