[Nuclei] Nuclei Templates

9 CVEs with a ProjectDiscovery Nuclei detection template

These vulnerabilities have a published Nuclei detection template in projectdiscovery/nuclei-templates. That means every bug bounty hunter, AppSec team, and red team is actively scanning the internet for them. Assume your exposed instances have already been touched.

CVE-2026-10520

Jun 9, 2026

Critical (10.0)

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...

Read Advisory

CVE-2026-48907

Jun 5, 2026

Critical (10.0)

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution....

Read Advisory

CVE-2026-9082

May 20, 2026

Medium (6.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1...

Read Advisory

CVE-2026-42271

May 8, 2026

High (8.8)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST ...

Read Advisory

CVE-2026-41940

Apr 29, 2026

Critical (9.8)

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel....

Read Advisory

CVE-2026-34197

Apr 7, 2026

High (8.8)

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bri...

Read Advisory

CVE-2025-34291

Dec 5, 2025

Critical (9.4)

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with all...

Read Advisory

CVE-2024-27199

Mar 4, 2024

High (7.3)

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible...

Read Advisory

CVE-2023-27351

Apr 20, 2023

High (7.5)

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The spe...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.