projectdiscovery / nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.
https://github.com/projectdiscovery/nuclei
MIT License
8.91k stars 2.55k forks source link

Increase Coverage of KEV Templates #7549

Open princechaddha opened 1 year ago

princechaddha commented 1 year ago

In this issue, We have compiled a list of KEV CVEs that have publicly available POCs. We are inviting contributions from the community to expand the coverage of Known Exploited Vulnerabilities (KEV) CVEs and make them accessible to everyone.

Expanding the coverage of widely exploited KEV CVEs in the nuclei-templates repository will enhance the detection capabilities and provide more comprehensive security scanning for a broader range of vulnerabilities. This contribution will significantly benefit the entire community by improving the overall effectiveness of vulnerability scanning.

We highly appreciate your involvement and eagerly look forward to your valuable contributions! To contribute, please refer to our Contribution Guide and explore the Nuclei Templates Documentation for further guidance.

If you require any assistance with writing templates or have questions about contributing, feel free to join our Discord server. Our community members will be more than happy to help you.

KEV CVEs

king-alexander commented 1 year ago

In the PoC for CVE-2022-26258, the payload is directed at a different endpoint than the one described, so I suggest it be removed from this list. There is an excellent writeup at https://vulncheck.com/blog/moobot-uses-fake-vulnerability with more details.

king-alexander commented 10 months ago

The template for CVE-2021-22205 already exists, authored by the GitLab Red Team.