projectdiscovery has 3 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Weakness classes
Products
- github.com/projectdiscovery/nuclei/v2 1
- github.com/projectdiscovery/nuclei/v3 1
- nuclei 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-92718High· 7.3Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums52CVE-2023-37896High· 7.5Nuclei Path Traversal vulnerability41CVE-2026-41282Medium· 5.3Nuclei: Environment variable disclosure via Response-Derived DSL Expressions29
projectdiscovery vulnerabilities
CVEs affecting projectdiscovery, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-92718High· 7.3PoCNuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modific…
▾ Midnightprojectdiscovery · nucleiEPSS 0.11%via NVD
CVE-2026-41282Medium· 5.3Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
▾ Sunlitprojectdiscovery · github.com/projectdiscovery/nuclei/v3EPSS 0.25%via OSV
CVE-2023-37896High· 7.5Nuclei Path Traversal vulnerability
Nuclei Path Traversal vulnerability
▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v2EPSS 1.0%via OSV