projectdiscovery
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/20/2026, projectdiscovery recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, nuclei had the most security vulnerabilities in the projectdiscovery ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-92718Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache | Exploitation statusNot confirmed | FixYes | Affected productnuclei | Published09/16/2026 | SeverityHigh |
CVE-2026-41645Nuclei: Environment variable disclosure via Response-Derived DSL Expressions | Exploitation statusNot known exploited | FixYes | Affected productnuclei | Published05/08/2026 | SeverityMedium |
CVE-2026-41646Nuclei: Local File Read via require() Module Loader Bypass | Exploitation statusPublic exploit | FixYes | Affected productnuclei | Published05/08/2026 | SeverityMedium |
CVE-2026-41282 | Exploitation statusPublic exploit | FixYes | Affected productnuclei | Published04/20/2026 | SeverityMedium |
CVE-2024-43405Nuclei Template Signature Verification Bypass | Exploitation statusPublic exploit | FixNot confirmed | Affected productnuclei | Published09/04/2024 | SeverityHigh |
CVE-2024-40641Unsigned code template execution through workflows in projectdiscovery/nuclei | Exploitation statusPublic exploit | FixNot confirmed | Affected productnuclei | Published07/17/2024 | SeverityHigh |
CVE-2024-5262ProjectDiscovery Interactsh - Files or Directories Accessible to External Parties | Exploitation statusNot known exploited | FixYes | Affected productinteractsh | Published06/05/2024 | SeverityCritical |
CVE-2024-27920Unsigned code template execution through workflows in projectdiscovery/nuclei | Exploitation statusNot known exploited | FixNot confirmed | Affected productnuclei | Published03/15/2024 | SeverityHigh |
CVE-2023-37896Nuclei Path Traversal vulnerability | Exploitation statusNot known exploited | FixYes | Affected productnuclei | Published08/04/2023 | SeverityHigh |
CVE-2023-36474Interactsh server settings make users vulnerable to Subdomain Takeover | Exploitation statusPublic exploit | FixNot confirmed | Affected productinteractsh | Published06/28/2023 | SeverityHigh |