Skip to content

Releases: projectdiscovery/nuclei-templates

v9.7.8 - Fishing for Phishing

11 Mar 18:21
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

In our latest release, we are thrilled to announce new addition of 120+ OSINT - Phishing Detection templates, thanks to the contributions of our community member @rxerium. These templates are accessible at Phishing Detection templates.

These templates are specifically added to help OSINT analysts, threat researchers, and security professionals in discovering and studying phishing campaigns therefore, we have added them to the OSINT scan profile here. Users can execute the OSINT scan configuration profile with nuclei -u <host> -config ~/nuclei-templates/config/osint.yml

Please note that these templates are not included in the default run. To use them, users can simply include them in the scan using nuclei -u <host> -tags phishing -itags phishing.

By identifying and analyzing phishing sites, OSINT analysts can discover patterns, monitor the activities of threat actors, and collect data essential for broader security research or investigative journalism. This makes it a valuable addition to the OSINT toolkit.

What's Changed

New Templates Added: 126

  • http/cves/2023/CVE-2023-43187.yaml by @0xParth
  • http/cves/2023/CVE-2023-5089.yaml by @JPG0mez
  • http/vulnerabilities/chanjet-tplus/chanjet-tplus-unauth-passreset.yaml by @0xr2r
  • http/exposed-panels/atlassian-bamboo-panel.yaml by @righettod
  • http/exposed-panels/cleanweb-panel.yaml by @righettod
  • http/exposed-panels/eset-protect-panel.yaml by @charles D.
  • http/exposed-panels/graylog-panel.yaml by @righettod
  • http/exposed-panels/lockself-panel.yaml by @righettod
  • http/exposed-panels/moodle-workplace-panel.yaml by @righettod
  • http/exposed-panels/nexus-panel.yaml by @righettod
  • http/exposed-panels/pahtool-panel.yaml by @righettod
  • http/technologies/hcpanywhere-detect.yaml by @righettod
  • http/technologies/admiralcloud-detect.yaml by @righettod
  • http/osint/phishing/1password-phish.yaml by @rxerium
  • http/osint/phishing/adobe-phish.yaml by @rxerium
  • http/osint/phishing/aliexpress-phish.yaml by @rxerium
  • http/osint/phishing/amazon-phish.yaml by @rxerium
  • http/osint/phishing/amazon-web-services-phish.yaml by @rxerium
  • http/osint/phishing/american-express-phish.yaml by @rxerium
  • http/osint/phishing/anydesk-phish.yaml by @rxerium
  • http/osint/phishing/avast-phish.yaml by @rxerium
  • http/osint/phishing/avg-phish.yaml by @rxerium
  • http/osint/phishing/bank-of-america-phish.yaml by @rxerium
  • http/osint/phishing/battlenet-phish.yaml by @rxerium
  • http/osint/phishing/bestbuy-phish.yaml by @rxerium
  • http/osint/phishing/bitdefender-phish.yaml by @rxerium
  • http/osint/phishing/bitwarden-phish.yaml by @rxerium
  • http/osint/phishing/blender-phish.yaml by @rxerium
  • http/osint/phishing/booking-phish.yaml by @rxerium
  • http/osint/phishing/box-storage-phish.yaml by @rxerium
  • http/osint/phishing/brave-phish.yaml by @rxerium
  • http/osint/phishing/brighthr-phish.yaml by @rxerium
  • http/osint/phishing/ccleaner-phish.yaml by @rxerium
  • http/osint/phishing/chase-phish.yaml by @rxerium
  • http/osint/phishing/chrome-phish.yaml by @rxerium
  • http/osint/phishing/costa-phish.yaml by @rxerium
  • http/osint/phishing/dashlane-phish.yaml by @rxerium
  • http/osint/phishing/deezer-phish.yaml by @rxerium
  • http/osint/phishing/deliveroo-phish.yaml by @rxerium
  • http/osint/phishing/digital-ocean-phish.yaml by @rxerium
  • http/osint/phishing/discord-phish.yaml by @rxerium
  • http/osint/phishing/disneyplus-phish.yaml by @rxerium
  • http/osint/phishing/dropbox-phish.yaml by @rxerium
  • http/osint/phishing/duckduckgo-phish.yaml by @rxerium
  • http/osint/phishing/ebay-phish.yaml by @rxerium
  • http/osint/phishing/edge-phish.yaml by @rxerium
  • http/osint/phishing/ee-mobile-phish.yaml by @rxerium
  • http/osint/phishing/eset-phish.yaml by @rxerium
  • http/osint/phishing/evernote-phish.yaml by @rxerium
  • http/osint/phishing/facebook-phish.yaml by @rxerium
  • http/osint/phishing/figma-phish.yaml by @rxerium
  • http/osint/phishing/filezilla-phish.yaml by @rxerium
  • http/osint/phishing/firefox-phish.yaml by @rxerium
  • http/osint/phishing/gimp-phish.yaml by @rxerium
  • http/osint/phishing/github-phish.yaml by @rxerium
  • http/osint/phishing/google-phish.yaml by @rxerium
  • http/osint/phishing/icloud-phish.yaml by @rxerium
  • http/osint/phishing/instagram-phish.yaml by @rxerium
  • http/osint/phishing/kaspersky-phish.yaml by @rxerium
  • http/osint/phishing/kayak-phish.yaml by @rxerium
  • http/osint/phishing/keepass-phish.yaml by @rxerium
  • http/osint/phishing/keepersecurity-phish.yaml by @rxerium
  • http/osint/phishing/keybase-phish.yaml by @rxerium
  • http/osint/phishing/lastpass-phish.yaml by @rxerium
  • http/osint/phishing/libre-office-phish.yaml by @rxerium
  • http/osint/phishing/linkedin-phish.yaml by @rxerium
  • http/osint/phishing/malwarebytes-phish.yaml by @rxerium
  • http/osint/phishing/mcafee-phish.yaml by @rxerium
  • http/osint/phishing/mega-phish.yaml by @rxerium
  • http/osint/phishing/messenger-phish.yaml by @rxerium
  • http/osint/phishing/microcenter-phish.yaml by @rxerium
  • http/osint/phishing/microsoft-phish.yaml by @rxerium
  • http/osint/phishing/microsoft-teams-phish.yaml by @rxerium
  • http/osint/phishing/netflix-phish.yaml by @rxerium
  • http/osint/phishing/nordpass-phish.yaml by @rxerium
  • http/osint/phishing/norton-phish.yaml by @rxerium
  • http/osint/phishing/notion-phish.yaml by @rxerium
  • http/osint/phishing/o2-mobile-phish.yaml by @rxerium
  • http/osint/phishing/openai-phish.yaml by @rxerium
  • http/osint/phishing/opera-phish.yaml by @rxerium
  • http/osint/phishing/paramountplus-phish.yaml by @rxerium
  • http/osint/phishing/paypal-phish.yaml by @rxerium
  • http/osint/phishing/pcloud-phish.yaml by @rxerium
  • http/osint/phishing/pintrest-phish.yaml by @rxerium
  • http/osint/phishing/plusnet-phish.yaml by @rxerium
  • http/osint/phishing/proton-phish.yaml by @rxerium
  • http/osint/phishing/putty-phish.yaml by @rxerium
  • http/osint/phishing/python-phish.yaml by @rxerium
  • http/osint/phishing/quora-phish.yaml by @rxerium
  • http/osint/phishing/reddit-phish.yaml by @rxerium
  • http/osint/phishing/roblox-phish.yaml by @rxerium
  • http/osint/phishing/roboform-phish.yaml by @rxerium
  • http/osint/phishing/royal-mail-phish.yaml by @rxerium
  • http/osint/phishing/samsung-phish.yaml by @rxerium
  • http/osint/phishing/signal-phish.yaml by @rxerium
  • http/osint/phishing/sky-phish.yaml by @rxerium
  • http/osint/phishing/skype-phish.yaml by @rxerium
  • http/osint/phishing/skyscanner-phish.yaml by @rxerium
  • http/osint/phishing/slack-phish.yaml by @rxerium
  • http/osint/phishing/sophos-phish.yaml by @rxerium
  • http/osint/phishing/spotify-phish.yaml by @rxerium
  • http/osint/phishing/steam-phish.yaml by @rxerium
  • http/osint/phishing/sync-storage-phish.yaml by @rxerium
  • http/osint/phishing/target-phish.yaml by @rxerium
  • http/osint/phishing/teamviewer-phish.yaml by @rxerium
  • http/osint/phishing/telegram-phish.yaml by @rxerium
  • http/osint/phishing/three-mobile-phish.yaml by @rxerium
  • http/osint/phishing/thunderbird-phish.yaml by @rxerium
  • http/osint/phishing/ticketmaster-phish.yaml by @rxerium
  • http/osint/phishing/tiktok-phish.yaml by @rxerium
  • http/osint/phishing/trading212-phish.yaml by @rxerium
  • http/osint/phishing/trend-micro-phish.yaml by @rxerium
  • http/osint/phishing/trip-phish.yaml by @rxerium
  • http/osint/phishing/twitch-phish.yaml by @rxerium
  • http/osint/phishing/uber-phish.yaml by @rxerium
  • http/osint/phishing/visual-studio-code-phish.yaml by @rxerium
  • http/osint/phishing/vlc-player-phish.yaml by @rxerium
  • http/osint/phishing/vodafone-phish.yaml by @rxerium
  • http/osint/phishing/vultr-phish.yaml by @rxerium
  • http/osint/phishing/walmart-phish.yaml by @rxerium
  • http/osint/phishing/wetransfer-phish.yaml by @rxerium
  • http/osint/phishing/whatsapp-phish.yaml by @rxerium
  • http/osint/phishing/wikipedia-phish.yaml by @rxerium
  • http/osint/phishing/winscp-phish.yaml by @rxerium
  • http/osint/phishing/yahoo-phish.yaml by @rxerium
  • http/osint/phishing/zoom-phish.yaml by @rxerium

New Contributors

Full Changelog: v9.7.7...v9.7.8

v9.7.7

06 Mar 10:57
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 82 | CVEs Added: 21 | First-time contributions: 8

New Contributors

Full Changelog: v9.7.6...v9.7.7

v9.7.6

20 Feb 16:29
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 49 | CVEs Added: 22 | First-time contributions: 12

New Contributors

Full Changelog: v9.7.5...v9.7.6

v9.7.5 - Local Privilege Escalation

30 Jan 08:36
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

In our latest release, we have added a significant number of trending CVEs and are excited to announce the addition of new local privilege escalation templates. These valuable contributions come from our community, with a notable contribution from @daffainfo, and are available at Local Privilege Escalation Templates. These templates utilize the newly introduced code protocol, enhancing their capability to detect vulnerabilities more effectively.

It's important to note that these templates are specifically designed for local execution to identify privilege escalation vulnerabilities. For security reasons, they are not executed as part of the default Nuclei scan. We ensure the security and authenticity of these templates by signing them officially. To run these templates, users need to provide the -code flag along with -itags local. These additions are particularly useful for penetration testing and red-teaming focusing on privilege escalation, and we plan to further expand their coverage in future updates. Following are the other highlights of this release:

What's Changed

New Templates Added: 106 | CVEs Added: 14 | First-time contributions: 14

  • javascript/cves/2024/CVE-2024-23897.yaml by @iamnoooob,@rootxharsh,@pdresearch 🔥
  • http/cves/2024/CVE-2024-0204.yaml by @dhiyaneshdk 🔥
  • http/cves/2023/CVE-2023-48023.yaml by @cookiehanhoan,@harryha
  • http/cves/2023/CVE-2023-47643.yaml by @isacaya
  • http/cves/2023/CVE-2023-47211.yaml by @gy741 🔥
  • http/cves/2023/CVE-2023-44352.yaml by @pwnwithlove
  • http/cves/2023/CVE-2023-27640.yaml by @mastercho
  • http/cves/2023/CVE-2023-27639.yaml by @mastercho
  • http/cves/2023/CVE-2023-22527.yaml by @Iamnooob,@rootxharsh,@pdresearch 🔥
  • http/cves/2023/CVE-2023-6977.yaml by @gy741
  • http/cves/2023/CVE-2023-6875.yaml by @iamnoooob,@rootxharsh,@pdresearch 🔥
  • http/cves/2023/CVE-2023-6023.yaml by @M0ck3d,@cookiehanhoan
  • http/cves/2019/CVE-2019-16469.yaml by @DomenicoVeneziano 🔥
  • http/cves/2018/CVE-2018-10942.yaml by @mastercho
  • http/vulnerabilities/apache/apache-nifi-rce.yaml by @arliya
  • http/vulnerabilities/juniper/junos-xss.yaml by @dhiyaneshdk
  • http/vulnerabilities/prestashop/prestashop-blocktestimonial-file-upload.yaml by @mastercho
  • http/vulnerabilities/vbulletin/vbulletin-backdoor.yaml by @mastercho
  • code/privilege-escalation/linux/binary/privesc-aa-exec.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-ash.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-awk.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-bash.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-cdist.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-choom.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-cpulimit.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-csh.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-csvtool.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-dash.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-dc.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-distcc.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-elvish.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-enscript.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-env.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-expect.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-find.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-fish.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-flock.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-gawk.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-grc.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-ionice.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-julia.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-lftp.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-ltrace.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-lua.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-mawk.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-multitime.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-mysql.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-nawk.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-nice.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-node.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-nsenter.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-perl.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-pexec.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-php.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-posh.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-python.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rake.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rc.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rlwrap.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rpm.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rpmdb.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-rpmverify.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-ruby.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-run-parts.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-sash.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-slsh.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-socat.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-softlimit.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-sqlite3.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-ssh-agent.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-sshpass.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-stdbuf.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-strace.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-tar.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-tcsh.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-time.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-timeout.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-tmate.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-torify.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-torsocks.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-unshare.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-vi.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-view.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-vim.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-xargs.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-xdg-user-dir.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-yash.yaml by @daffainfo
  • code/privilege-escalation/linux/binary/privesc-zsh.yaml by @daffainfo
  • code/privilege-escalation/linux/rw-shadow.yaml by @daffainfo
  • code/privilege-escalation/linux/rw-sudoers.yaml by @daffainfo
  • code/privilege-escalation/linux/sudo-nopasswd.yaml by @daffainfo
  • code/privilege-escalation/linux/writable-etc-passwd.yaml by @daffainfo
  • http/default-logins/node-red/nodered-default-login.yaml by @savik
  • http/default-logins/powershell/powershell-default-login.yaml by @ap3r
  • http/exposed-panels/autoset-detect.yaml by @mastercho
  • http/exposed-panels/compalex-panel-detect.yaml by @mastercho
  • http/exposed-panels/doris-panel.yaml by @ritikchaddha
  • http/exposed-panels/lomnido-panel.yaml by @righettod
  • http/exposures/configs/vbulletin-path-disclosure.yaml by @mastercho
  • http/exposures/logs/go-pprof-debug.yaml by @w8ay
  • http/miscellaneous/defacement-detect.yaml by @ricardomaia
  • http/misconfiguration/doris-dashboard.yaml by @ritikchaddha
  • http/misconfiguration/springboot/springboot-integrationgraph.yaml by @ELSFA7110
  • http/misconfiguration/springboot/springboot-startup.yaml by @ELSFA7110
  • http/technologies/tibco-businessconnect-detect.yaml by @righettod
  • dns/dns-rebinding.yaml by @ricardomaia

New Contributors

Read more

v9.7.4

16 Jan 21:32
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

Full Changelog: v9.7.3...v9.7.4

v9.7.3

14 Jan 14:14
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 45 | CVEs Added: 16 | First-time contributions: 6

New Contributors

Full Changelog: v9.7.2...v9.7.3

v9.7.2

22 Dec 05:08
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 61 | CVEs Added: 25 | First-time contributions: 8

New Contributors

Full Changelog: v9.7.1...v9.7.2

v9.7.1

02 Dec 07:27
Compare
Choose a tag to compare

What's Changed

Full Changelog: v9.7.0...v9.7.1

v9.7.0

01 Dec 16:42
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 51 | CVEs Added: 18 | First-time contributions: 7

New Contributors

Full Changelog: v9.6.9...v9.7.0

v9.6.9

10 Nov 10:43
Compare
Choose a tag to compare

🔥 Release Highlights 🔥

What's Changed

New Templates Added: 73 | CVEs Added: 13 | First-time contributions: 7

New Contributors

Full Changelog: v9.6.8...v9.6.9