<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — nuclei</title>
  <link>https://appsec.fyi/tools.html#nuclei</link>
  <description>Curated nuclei resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/tool/nuclei.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sun, 07 Jun 2026 04:05:35 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>Recon-Script: automation with Nuclei (s1d6point7bugcrowd)</title>
    <link>https://github.com/s1d6point7bugcrowd/Recon-Script</link>
    <guid isPermaLink="true">https://github.com/s1d6point7bugcrowd/Recon-Script</guid>
    <description>Library for automating Nuclei vulnerability scans, integrating features like voice notifications via espeak, proxychains support, and optional cloud uploads to ProjectDiscovery Cloud Platform (PDCP). It allows for out-of-scope filtering, custom bug bounty headers, and detailed scan logging with timestamps, supporting tools such as subfinder, dnsx, and httpx.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 17 Apr 2026 14:54:29 +0000</pubDate>
  </item>
  <item>
    <title>The Ultimate Guide to Finding Bugs With Nuclei (ProjectDiscovery)</title>
    <link>https://projectdiscovery.io/blog/ultimate-nuclei-guide</link>
    <guid isPermaLink="true">https://projectdiscovery.io/blog/ultimate-nuclei-guide</guid>
    <description>Library for efficient, extensible vulnerability scanning using YAML-based templates. Nuclei supports HTTP, DNS, SSL, and raw TCP protocols, allowing detection of CVEs, misconfigurations, and sensitive file exposures. It integrates into workflows with other tools and offers features like custom template creation, fuzzing, advanced DSL for matchers, and various scan modes including headless and network. Advanced options include rate limiting, template filtering by technology, severity, or name, and resuming interrupted scans.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 17 Apr 2026 14:14:14 +0000</pubDate>
  </item>
  <item>
    <title>Automate Your Nuclei Recon Pipeline with VPN + Discord Alerts</title>
    <link>https://www.mousebrothers.com/automated-nuclei-recon-pipeline/</link>
    <guid isPermaLink="true">https://www.mousebrothers.com/automated-nuclei-recon-pipeline/</guid>
    <description>Script automates bug bounty reconnaissance by enumerating subdomains with subfinder, probing live hosts via httpx, rotating NordVPN IPs, and running Nuclei scans with specific templates and filters. It sends Discord alerts for any found vulnerabilities, detailing the count, severity, template ID, matched target, and current IP. The process is designed for repeatable, single-command execution on a list of target domains.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 17 Apr 2026 14:14:11 +0000</pubDate>
  </item>
  <item>
    <title>From Recon to Sensitive Key Exposure Using Nuclei</title>
    <link>https://medium.com/@mohamedsinger837/from-recon-to-sensitive-key-exposure-finding-leaked-secrets-using-nuclei-subfinder-katana-429d2ce705ae</link>
    <guid isPermaLink="true">https://medium.com/@mohamedsinger837/from-recon-to-sensitive-key-exposure-finding-leaked-secrets-using-nuclei-subfinder-katana-429d2ce705ae</guid>
    <description>From Recon to Sensitive Key Exposure Using Nuclei</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Thu, 16 Apr 2026 21:04:33 +0000</pubDate>
  </item>
  <item>
    <title>Automating Bug Bounties with Nuclei</title>
    <link>https://bugbase.ai/blog/automating-bug-bounties-with-nuclei</link>
    <guid isPermaLink="true">https://bugbase.ai/blog/automating-bug-bounties-with-nuclei</guid>
    <description>Automating Bug Bounties with Nuclei</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Thu, 16 Apr 2026 21:03:14 +0000</pubDate>
  </item>
  <item>
    <title>Advanced Techniques &amp; Use Cases of Nuclei for Bug Bounty</title>
    <link>https://osintteam.blog/advanced-techniques-use-cases-of-nuclei-for-bug-bounty-22be32c09d1b</link>
    <guid isPermaLink="true">https://osintteam.blog/advanced-techniques-use-cases-of-nuclei-for-bug-bounty-22be32c09d1b</guid>
    <description>Advanced Techniques &amp; Use Cases of Nuclei for Bug Bounty</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Thu, 16 Apr 2026 21:03:14 +0000</pubDate>
  </item>
  <item>
    <title>NucleiFuzzer - Powerful Automation Tool For Detecting XSS, SQLi, SSRF, Open</title>
    <link>https://www.kitploit.com/2023/09/nucleifuzzer-powerful-automation-tool.html?m=1</link>
    <guid isPermaLink="true">https://www.kitploit.com/2023/09/nucleifuzzer-powerful-automation-tool.html?m=1</guid>
    <description>&quot;NucleiFuzzer is an automation tool designed to detect vulnerabilities like XSS, SQLi, SSRF, and Open. It offers powerful capabilities for automated testing and identification of security flaws in web applications.&quot;</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Thu, 14 Aug 2025 11:05:19 +0000</pubDate>
  </item>
  <item>
    <title>NucleiFuzzer - Powerful Automation Tool For Detecting XSS, SQLi, SSRF, Open</title>
    <link>https://www.kitploit.com/2023/09/nucleifuzzer-powerful-automation-tool.html</link>
    <guid isPermaLink="true">https://www.kitploit.com/2023/09/nucleifuzzer-powerful-automation-tool.html</guid>
    <description>&quot;NucleiFuzzer is an automation tool designed to detect vulnerabilities like XSS, SQLi, SSRF, and Open. It offers powerful capabilities for automated security testing.&quot;</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Thu, 14 Aug 2025 03:58:38 +0000</pubDate>
  </item>
  <item>
    <title>New CVE : CVE-2025-4123 Grafana open redirect XSS/SSRF via path traversal Detect it now with Nuclei template #infosec #cve #nuclei #grafana #ssrf #xss #openredirect</title>
    <link>https://x.com/pdiscoveryio/status/1925536778787954961</link>
    <guid isPermaLink="true">https://x.com/pdiscoveryio/status/1925536778787954961</guid>
    <description>A new CVE, CVE-2025-4123, highlights a vulnerability in Grafana that allows open redirect, XSS, and SSRF via path traversal. The issue can be detected using Nuclei template. The post emphasizes the importance of addressing this security concern in Grafana. #infosec #cve #nuclei #grafana #ssrf #xss #openredirect.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">news</category>
    <pubDate>Thu, 22 May 2025 13:33:32 +0000</pubDate>
  </item>
  <item>
    <title>Simplifying XSS Detection with Nuclei - A New Approach</title>
    <link>https://blog.projectdiscovery.io/simplifying-xss-detection-with-nuclei/</link>
    <guid isPermaLink="true">https://blog.projectdiscovery.io/simplifying-xss-detection-with-nuclei/</guid>
    <description>Library for simplifying XSS detection, leveraging Nuclei&#x27;s headless mode and the `waitdialog` action. This technique mimics real user interactions by running JavaScript, allowing for detection of XSS payload execution via JavaScript dialogs rather than relying on complex, target-specific reflection-based string matchers. The headless approach offers higher accuracy and reduced complexity, making XSS detection more consistent across different web applications.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Thu, 26 Sep 2024 01:36:18 +0000</pubDate>
  </item>
  <item>
    <title>Cybersleuth254: Found an SSRF vulnerability using a custom Nuclei template! This bug allows attackers to inject malicious URLs and access sensitive data on the server. #Cybersecurity #SSRF #BugBounty #PenTesting #Infosec #Nuclei</title>
    <link>https://x.com/Cybersleuth254/status/1836375797243723961</link>
    <guid isPermaLink="true">https://x.com/Cybersleuth254/status/1836375797243723961</guid>
    <description>Cybersleuth254 discovered an SSRF vulnerability using a custom Nuclei template, enabling attackers to inject malicious URLs and access sensitive server data. The finding highlights the importance of cybersecurity measures like bug bounties, penetration testing, and information security. #Cybersecurity #SSRF #BugBounty #PenTesting #Infosec #Nuclei.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Wed, 18 Sep 2024 13:13:48 +0000</pubDate>
  </item>
  <item>
    <title>Cybersleuth254: Found an SSRF vulnerability using a custom Nuclei template! This bug allows attackers to inject malicious URLs and access sensitive data on the server. Always validate inputs to prevent these threats! #Cybersecurity #SSRF #BugBounty #PenTesting #Infosec #Nuclei</title>
    <link>https://x.com/Cybersleuth254/status/1836375638644543728</link>
    <guid isPermaLink="true">https://x.com/Cybersleuth254/status/1836375638644543728</guid>
    <description>Cybersleuth254 discovered an SSRF vulnerability using a custom Nuclei template, enabling attackers to inject malicious URLs and access sensitive server data. The importance of input validation to prevent such threats is emphasized. The post highlights cybersecurity, SSRF, bug bounty, penetration testing, and Nuclei.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Wed, 18 Sep 2024 13:13:48 +0000</pubDate>
  </item>
  <item>
    <title>The Ultimate Guide to Finding Bugs With Nuclei</title>
    <link>https://blog.projectdiscovery.io/ultimate-nuclei-guide/</link>
    <guid isPermaLink="true">https://blog.projectdiscovery.io/ultimate-nuclei-guide/</guid>
    <description>Library for efficient, extensible vulnerability scanning using YAML-based templates. Nuclei supports HTTP, DNS, SSL, and raw TCP protocols, allowing users to define custom checks for vulnerabilities. It can scan thousands of hosts rapidly, integrates into existing workflows, and offers template filtering by technology, severity, or CVE. Advanced features include custom template creation, fuzzing, multi-step interactions, and support for network, DNS, file, and headless modes.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 11 Aug 2023 04:14:01 +0000</pubDate>
  </item>
  <item>
    <title>Favorite tweet by @ptracesecurity</title>
    <link>https://twitter.com/ptracesecurity/status/1498961557937659909</link>
    <guid isPermaLink="true">https://twitter.com/ptracesecurity/status/1498961557937659909</guid>
    <description>Favorite tweet:

Nuclei-Burp Extension: run nuclei scanner directly from burp https://t.co/5eXxgjapf7 #Pentesting #BurpSuite #WebSecurity #Infosec https://t.co/xwhsoQfhRo

— Ptrace Security GmbH (@ptr...</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Wed, 02 Mar 2022 20:42:55 +0000</pubDate>
  </item>
  <item>
    <title>Install Nuclei</title>
    <link>https://github.com/projectdiscovery/nuclei?mc_cid=04f49feac0</link>
    <guid isPermaLink="true">https://github.com/projectdiscovery/nuclei?mc_cid=04f49feac0</guid>
    <description>Library for fast, template-based vulnerability scanning using simple YAML templates. It supports multiple protocols like HTTP, DNS, and TCP, and can be integrated into CI/CD pipelines. Nuclei allows for custom vulnerability detection scenarios to reduce false positives and includes integrations with tools like Jira, Splunk, and GitHub. The tool requires Go version 1.24.2 or later for installation.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Mon, 10 Jan 2022 23:37:00 +0000</pubDate>
  </item>
  <item>
    <title>Nuclei Templates</title>
    <link>https://github.com/projectdiscovery/nuclei-templates</link>
    <guid isPermaLink="true">https://github.com/projectdiscovery/nuclei-templates</guid>
    <description>Library of community-curated templates for the nuclei scanner, designed to detect various application security vulnerabilities. This repository houses templates developed by the project team and contributions from the security community, covering diverse attack vectors. Detailed documentation for creating custom templates is available, alongside statistics on template attributes like tags, author, severity, and type. Community engagement is encouraged through GitHub discussions and a Discord server for direct interaction with maintainers.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Mon, 10 Jan 2022 23:37:00 +0000</pubDate>
  </item>
  <item>
    <title>Install Nuclei</title>
    <link>https://github.com/projectdiscovery/nuclei</link>
    <guid isPermaLink="true">https://github.com/projectdiscovery/nuclei</guid>
    <description>Tool for high-performance vulnerability scanning, Nuclei uses simple YAML templates for custom detection scenarios, minimizing false positives through real-world simulation. It supports numerous protocols including HTTP, DNS, and TCP, integrates with CI/CD pipelines, and offers extensive filtering and output options. Installation requires Go version 1.24.2 or later.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Wed, 24 Nov 2021 02:07:00 +0000</pubDate>
  </item>
  <item>
    <title>Mobile Nuclei Templates</title>
    <link>https://github.com/optiv/mobile-nuclei-templates</link>
    <guid isPermaLink="true">https://github.com/optiv/mobile-nuclei-templates</guid>
    <description>Library of Nuclei templates designed for mobile security assessments. It includes specific templates for Android applications, focusing on `smali` checks. A dedicated `Keys` folder provides templates to identify API keys using regex patterns on decompiled Android apps, local code repositories, or unzipped IPA files. Users should install Nuclei from its GitHub repository to utilize these templates effectively for targeted mobile app analysis.</description>
    <category domain="tool">nuclei</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 11 Jun 2021 03:25:00 +0000</pubDate>
  </item>
</channel>
</rss>