Path to this page:
./
security/nuclei,
Fast and customizable vulnerability scanner
Branch: CURRENT,
Version: 3.3.9,
Package name: nuclei-3.3.9,
Maintainer: leotNuclei is used to send requests across targets based on a template,
leading to zero false positives and providing fast scanning on a large
number of hosts. Nuclei offers scanning for a variety of protocols,
including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.
With powerful and flexible templating, Nuclei can be used to model all
kinds of security checks.
Master sites:
Filesize: 11618.433 KB
Version history: (Expand)
- (2025-03-02) Updated to version: nuclei-3.3.9
- (2024-09-06) Updated to version: nuclei-3.2.8nb5
- (2024-08-11) Updated to version: nuclei-3.2.8nb4
- (2024-07-03) Updated to version: nuclei-3.2.8nb3
- (2024-06-13) Updated to version: nuclei-3.2.8nb2
- (2024-06-01) Updated to version: nuclei-3.2.8nb1
CVS history: (Expand)
2025-03-02 20:02:20 by Leonardo Taccari | Files touched by this commit (3) |
Log message:
nuclei: Update to 3.3.9
Changes:
v3.3.9
* Added `-ai` option to generate and run nuclei templates on the fly in
natural langauge
* Added initial Live DAST Server API implementation (experimental)
* Added support for DSL expression evaluation in headless args
* Bug fixes
v3.3.8
* Bug fixes
v3.3.7
* Added `OS_MAX_THREADS_ENV` environment variable to control the
maximum number of OS threads the Go program can utilize
* Added `-enable-global-matchers`option to control the execution of
global matchers
* Bug fixes
v3.3.6
* (Breaking change) The `-enable-self-contained` or `-esc` flag is now
required to load self-contained templates.
* (Breaking change) The `-file` flag must be used to enable loading
file templates.
* Added analyzer support and time based delay analyzer for DAST mode
* Added batch output support for JSONL output format
* Added ENV variable handling in dynamic secret file
* Bug fixes
v3.3.5
* Added support for global matchers / extractors in http templates
* Added support for MongoDB for results reporting
* Added support for `stop-at-first-match` in network templates
* Bug fixes
v3.3.4
* Fixed (hopefully) skipping target list as found unresponsive erroneously
v3.3.3
* Added linear issue tracker support
* Added support for additional headless lifecycle events
* Bug fixes
v3.3.2
* Fixed security issue in template `signer` package
* Added `ActionWaitDialog` type in headless protocol to simplify XSS detection
v3.3.1
* Added `team-id` option to upload results to specific team workspace
* Added redaction support in output file
* Added support for multiple auth strategies per target from secret file
* Added support to generate matcher-status event for javascript protocol
* Added `skip-secret-file` template attribute to disable auth per template
* Bug fixes
v3.3.0
* Bug fixes
v3.2.9
* Fuzzing feature enhancements
- Added `part: request` to fuzz all the keys in request with fuzzing
templates.
- Added `-fuzz-aggression` CLI option to control fuzz aggression via
template.
- Added `-fuzz-param-frequency` option to control counter for skipping
uninteresting parameter.
- Added `-display-fuzz-points` option to display fuzzing points
(for debugging).
* PDCP Team ID input support via environment variable to upload results into
team account
* Bug fixes
|
2024-09-06 20:49:02 by Benny Siegert | Files touched by this commit (180) |  |
Log message:
Revbump all Go packages after go122 update
|
2024-08-11 17:57:15 by Benny Siegert | Files touched by this commit (176) |  |
Log message:
Revbump all Go packages after update
|
2024-07-03 08:59:36 by Benny Siegert | Files touched by this commit (169) |  |
Log message:
Revbump all Go packages after go122 security update
|
2024-06-13 15:47:13 by Benny Siegert | Files touched by this commit (169) |  |
Log message:
Revbump all Go packages after go122 update
|
2024-06-01 16:03:06 by Benny Siegert | Files touched by this commit (168) |
Log message:
Revbump all Go packages, default Go version is now 1.22.
|
2024-05-27 22:34:03 by Leonardo Taccari | Files touched by this commit (3) |
Log message:
nuclei: Update to 3.2.8
Changes:
v3.2.8
- Bug Fixes
v3.2.7
- Added support for multiple search query in templates to run with
`-uncover` option
- Added `-scan-name` input support for pdcp result upload
- Bug Fixes
v3.2.6
- Fixed goroutine leaks causing spike in memory uses
- Added `-profile` and `-profile-list` option to run template using
template profile
- Added template tags list (`-tgl`) option
- Added fuzzing output enhancements
v3.2.5
- Added query variable to read param values
- Added SRV query in dns protocol
- Added response read timeout flag for network request
- Added networkpolicy to httpx probes
- Added context vars in code and multi protocol
- Added nuclei stats / chart utils
- Added support for context cancellation to engine (SDK)
- Added support for user provided catalog (SDK)
- Added embedded api for settings control in CLI modality (WIP)
- Added initial refactor for speed control (WIP)
- Bug fixes
v3.2.4
- Fixed an issue for templates with dynamic extractor + payloads edgecase
- Bug fixes
v3.2.3
- Added `-dast` option to run all and only dast (fuzz) templates
- Added `pre-condition` attribute in Code and DAST templates
- Bug fixes
|
2024-04-05 21:14:14 by Benny Siegert | Files touched by this commit (161) |  |
Log message:
Revbump all Go packages after go121 update
|