Skip to content

Commit 6c4d0c6

Browse files
authored
Merge branch 'main' into addtimebased
2 parents 3bff635 + 6db1585 commit 6c4d0c6

File tree

285 files changed

+8690
-6133
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

285 files changed

+8690
-6133
lines changed

.new-additions

Lines changed: 36 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -1,69 +1,36 @@
1-
code/cves/2024/CVE-2024-4340.yaml
2-
code/cves/2024/CVE-2024-45409.yaml
3-
http/cves/2017/CVE-2017-5871.yaml
4-
http/cves/2019/CVE-2019-19411.yaml
5-
http/cves/2021/CVE-2021-25094.yaml
6-
http/cves/2021/CVE-2021-40272.yaml
7-
http/cves/2023/CVE-2023-0676.yaml
8-
http/cves/2023/CVE-2023-27641.yaml
9-
http/cves/2023/CVE-2023-39007.yaml
10-
http/cves/2023/CVE-2023-4151.yaml
11-
http/cves/2023/CVE-2023-47105.yaml
12-
http/cves/2024/CVE-2024-3234.yaml
13-
http/cves/2024/CVE-2024-32964.yaml
14-
http/cves/2024/CVE-2024-35627.yaml
15-
http/cves/2024/CVE-2024-3753.yaml
16-
http/cves/2024/CVE-2024-38816.yaml
17-
http/cves/2024/CVE-2024-43160.yaml
18-
http/cves/2024/CVE-2024-43917.yaml
19-
http/cves/2024/CVE-2024-45440.yaml
20-
http/cves/2024/CVE-2024-46627.yaml
21-
http/cves/2024/CVE-2024-4940.yaml
22-
http/cves/2024/CVE-2024-5488.yaml
23-
http/cves/2024/CVE-2024-6517.yaml
24-
http/cves/2024/CVE-2024-7354.yaml
25-
http/cves/2024/CVE-2024-7714.yaml
26-
http/cves/2024/CVE-2024-7854.yaml
27-
http/cves/2024/CVE-2024-8021.yaml
28-
http/cves/2024/CVE-2024-8877.yaml
29-
http/cves/2024/CVE-2024-9463.yaml
30-
http/cves/2024/CVE-2024-9465.yaml
31-
http/default-logins/datagerry/datagerry-default-login.yaml
32-
http/default-logins/netdisco/netdisco-default-login.yaml
33-
http/exposed-panels/dockwatch-panel.yaml
34-
http/exposed-panels/enablix-panel.yaml
35-
http/exposed-panels/gitlab-explore.yaml
36-
http/exposed-panels/gitlab-saml.yaml
37-
http/exposed-panels/loxone-web-panel.yaml
38-
http/exposed-panels/m-bus-panel.yaml
39-
http/exposed-panels/macos-server-panel.yaml
40-
http/exposed-panels/riello-netman204-panel.yaml
41-
http/exposed-panels/rstudio-panel.yaml
42-
http/exposed-panels/saia-pcd-panel.yaml
43-
http/exposed-panels/workspace-one-uem-ssp.yaml
44-
http/exposures/logs/action-controller-exception.yaml
45-
http/exposures/logs/delphi-mvc-exception.yaml
46-
http/exposures/logs/expression-engine-exception.yaml
47-
http/exposures/logs/lua-runtime-error.yaml
48-
http/exposures/logs/mako-runtime-error.yaml
49-
http/exposures/logs/microsoft-runtime-error.yaml
50-
http/exposures/logs/mongodb-exception-page.yaml
51-
http/exposures/logs/sap-logon-error-message.yaml
52-
http/exposures/logs/twig-runtime-error.yaml
53-
http/miscellaneous/seized-site.yaml
54-
http/misconfiguration/ariang-debug-console.yaml
55-
http/misconfiguration/microsoft/aspnetcore-dev-env.yaml
56-
http/misconfiguration/netdisco/netdisco-unauth.yaml
57-
http/technologies/arcgis-detect.yaml
58-
http/technologies/dizquetv-detect.yaml
59-
http/technologies/ivanti-epm-detect.yaml
60-
http/technologies/microsoft/default-azure-function-app.yaml
61-
http/technologies/vertigis-detect.yaml
62-
http/technologies/wiki-js-detect.yaml
63-
http/technologies/windows-communication-foundation-detect.yaml
64-
http/technologies/wordpress/plugins/unlimited-elements-for-elementor.yaml
65-
http/token-spray/api-delighted.yaml
66-
http/token-spray/api-intigriti.yaml
67-
http/token-spray/api-telegram.yaml
68-
http/vulnerabilities/retool/retool-svg-xss.yaml
69-
http/vulnerabilities/wordpress/ninja-forms-xss.yaml
1+
http/cves/2015/CVE-2015-8562.yaml
2+
http/cves/2018/CVE-2018-7192.yaml
3+
http/cves/2018/CVE-2018-7193.yaml
4+
http/cves/2018/CVE-2018-7196.yaml
5+
http/cves/2021/CVE-2021-45811.yaml
6+
http/cves/2023/CVE-2023-1315.yaml
7+
http/cves/2023/CVE-2023-1317.yaml
8+
http/cves/2023/CVE-2023-1318.yaml
9+
http/cves/2024/CVE-2024-32735.yaml
10+
http/cves/2024/CVE-2024-32736.yaml
11+
http/cves/2024/CVE-2024-32737.yaml
12+
http/cves/2024/CVE-2024-32738.yaml
13+
http/cves/2024/CVE-2024-32739.yaml
14+
http/cves/2024/CVE-2024-39713.yaml
15+
http/cves/2024/CVE-2024-43360.yaml
16+
http/cves/2024/CVE-2024-44349.yaml
17+
http/cves/2024/CVE-2024-45488.yaml
18+
http/cves/2024/CVE-2024-46310.yaml
19+
http/cves/2024/CVE-2024-5910.yaml
20+
http/default-logins/zebra/zebra-printer-default-login.yaml
21+
http/exposed-panels/freescout-panel.yaml
22+
http/exposed-panels/paloalto-expedition-panel.yaml
23+
http/exposed-panels/sqlpad-panel.yaml
24+
http/exposed-panels/traccar-panel.yaml
25+
http/exposed-panels/txadmin-panel.yaml
26+
http/exposed-panels/usermin-panel.yaml
27+
http/exposed-panels/veritas-netbackup-panel.yaml
28+
http/exposed-panels/vmware-aria-panel.yaml
29+
http/misconfiguration/root-path-disclosure.yaml
30+
http/technologies/accellion-detect.yaml
31+
http/technologies/mirth-connect-detect.yaml
32+
http/technologies/oracle-fusion-detect.yaml
33+
http/technologies/wordpress/plugins/burst-statistics.yaml
34+
http/vulnerabilities/yonyou/yonyou-u8-crm-sqli.yaml
35+
http/vulnerabilities/yonyou/yonyou-u8-crm-tb-sqli.yaml
36+
passive/cves/2024/CVE-2024-40711.yaml

CONTRIBUTING.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ Along with the P.O.C following are the required fields in the info section for s
5656
- If there are more than 1 template for a tech create a separate folder for it
5757
- Don't share any vulnerable URL publicly on Github or Discord channel.
5858
- We should only upload a web shell as a last resort to validate the vulnerability, and if we do upload a file, make sure the file name is random(`{{randstr}}`)
59+
- Do not include code templates for exploits that can be written using HTTP or JavaScript. We avoid adding additional exploit code to the project unless there is an exception.
5960

6061
### **Submitting a PR**
6162

Community-Rewards-FAQ.md

Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
# Nuclei Templates Community Rewards Program - FAQ
2+
3+
## What is the purpose of this rewards program?
4+
The program is designed to reward the community for their efforts in contributing high-quality templates for critical and trending vulnerabilities.
5+
6+
## What are the bounty ranges for template submissions?
7+
Bounties range from **$50 to $250**, depending on the complexity of the template and the effort required.
8+
9+
## Where can I find bounty issues?
10+
Only issues listed by us on our GitHub repository with the 💎 **Bounty** label are eligible for rewards. You can find these bounty issues [here](https://github.com/projectdiscovery/nuclei-templates/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22%F0%9F%92%8E%20Bounty%22)
11+
12+
## What is the acceptance criteria for templates?
13+
Templates must meet the following criteria:
14+
1. **Complete POC**: A full Proof of Concept (POC) must be provided and not rely solely on version detection.
15+
2. **Debug Data**: Include debug data to assist with template validation.
16+
3. **Validation Required**: The template will be reviewed and validated before rewards are given.
17+
4. **Accurate Matchers**: Use strong matchers to avoid false positives.
18+
> **Note**: Triagers will make the final decision on whether a template qualifies for a reward based on validation and the acceptance criteria outlined.
19+
20+
## How do I start working on a bounty issue?
21+
1. **Find an Issue**: Look for issues tagged with 💎 **Bounty**.
22+
2. **Declare Work**: Comment with `/attempt #<issue_number>` to claim the issue.
23+
3. **Submit Work**: Submit your pull request with `/claim #<issue_number>` in the PR description when ready.
24+
25+
## How often are new bounty issues added?
26+
We add new bounty issues on a **weekly basis**, so make sure to check back regularly for fresh opportunities. In the future, you can expect many more bounty issues as the program expands, allowing more opportunities for contributors to participate and earn rewards.
27+
28+
## Can I collaborate with others?
29+
Yes, you can collaborate with other contributors and split rewards by commenting:
30+
```
31+
/claim #<issue_number>
32+
/split @contributor1
33+
/split @contributor2
34+
```
35+
36+
## Is there a limit to how many issues I can work on?
37+
You can work on up to **3 issues** simultaneously.
38+
39+
## What happens if I don’t complete an issue on time?
40+
Issues must be completed within **2 months**, or they will be closed.
41+
42+
## How are rewards distributed?
43+
Rewards are distributed once the template is fully validated. If the issue remains unresolved for **few weeks**, the bounty may increase.
44+
45+
## What should I include in my template submission?
46+
Include the following:
47+
- **Complete POC**: A working Proof of Concept.
48+
- **Matchers**: Multiple matchers to prevent false positives.
49+
- **Debug Data**: Data to assist the triage team in validation.
50+
- **Metadata**: Include required fields like `id`, `name`, `author`, `severity`, `description`, and `reference`.
51+
52+
## What types of templates will be rejected?
53+
Templates may be rejected if they:
54+
- Rely solely on version detection.
55+
- Lack a complete POC.
56+
- Contain weak matchers or redundant changes to existing templates.
57+
58+
## What should I avoid when submitting a template?
59+
- Avoid sharing real-world targets publicly.
60+
- Don’t submit templates with weak matchers.
61+
- Avoid unnecessary changes to existing templates.
62+
63+
## Is there a leaderboard for contributors?
64+
Yes! We now have a **leaderboard** that showcases top contributors. You can check it out here: [Leaderboard](https://cloud.projectdiscovery.io/templates/leaderboard).
65+
66+
## Is this program permanent?
67+
The rewards program is currently a test run, but we may make changes based on community feedback.
68+
69+
## What additional rewards are available besides bounties?
70+
Beyond bounties, we also reward contributors with:
71+
- **Swag** such as t-shirts and stickers.
72+
- **Invites to security conferences** for standout contributors.
73+
- **Stickers** as a token of appreciation for all first-time contributors, regardless of the bounty.
74+
75+
> Contributors who feel their pull request or issue was overlooked for first-time contributor stickers can ping us on our Discord for assistance: [ProjectDiscovery Discord](https://discord.com/invite/projectdiscovery).

README.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -42,18 +42,18 @@ An overview of the nuclei template project, including statistics on unique tags,
4242

4343
| TAG | COUNT | AUTHOR | COUNT | DIRECTORY | COUNT | SEVERITY | COUNT | TYPE | COUNT |
4444
|-----------|-------|---------------|-------|------------|-------|----------|-------|------|-------|
45-
| cve | 2743 | dhiyaneshdk | 1397 | http | 7977 | info | 3855 | file | 402 |
46-
| panel | 1201 | daffainfo | 866 | file | 402 | high | 2033 | dns | 25 |
47-
| wordpress | 1035 | dwisiswant0 | 802 | cloud | 325 | medium | 1727 | | |
48-
| exposure | 994 | princechaddha | 497 | workflows | 192 | critical | 1145 | | |
49-
| xss | 945 | pussycat0x | 451 | network | 137 | low | 279 | | |
50-
| wp-plugin | 904 | ritikchaddha | 445 | code | 82 | unknown | 43 | | |
45+
| cve | 2773 | dhiyaneshdk | 1420 | http | 8042 | info | 3887 | file | 402 |
46+
| panel | 1212 | daffainfo | 866 | file | 402 | high | 2039 | dns | 25 |
47+
| wordpress | 1046 | dwisiswant0 | 802 | cloud | 325 | medium | 1742 | | |
48+
| exposure | 997 | princechaddha | 498 | workflows | 192 | critical | 1158 | | |
49+
| xss | 956 | ritikchaddha | 455 | network | 137 | low | 280 | | |
50+
| wp-plugin | 915 | pussycat0x | 452 | code | 84 | unknown | 43 | | |
5151
| osint | 807 | pikpikcu | 353 | javascript | 65 | | | | |
52-
| tech | 722 | pdteam | 302 | ssl | 30 | | | | |
53-
| lfi | 712 | ricardomaia | 243 | dast | 25 | | | | |
54-
| misconfig | 710 | geeknik | 231 | dns | 22 | | | | |
52+
| tech | 729 | pdteam | 302 | ssl | 30 | | | | |
53+
| lfi | 713 | ricardomaia | 243 | dast | 25 | | | | |
54+
| misconfig | 713 | geeknik | 231 | dns | 22 | | | | |
5555

56-
**718 directories, 9584 files**.
56+
**723 directories, 9654 files**.
5757

5858
</td>
5959
</tr>

TEMPLATES-STATS.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)