v10.2.4

projectdiscovery/nuclei-templatesv10.2.4Jul 1, 2025by princechaddha

AI Summary

Added 67 new templates focusing on legacy and critical vulnerabilities including Microsoft SMBv3 RCE, Apache HTTP Server flaws, and new panel detection templates for printers and Kubernetes.

Key Highlights

  • Pterodactyl Panel Remote Code Execution (CVE-2025-49132)
  • GeoServer WFS XXE Processing Vulnerability (CVE-2025-30220)
  • Microsoft SMBv3 Remote Code Execution (CVE-2020-0796)
  • Apache HTTP Server mod_proxy_uwsgi RCE (CVE-2020-11984)
  • Microsoft SharePoint RCE (CVE-2019-0604)

Breaking Changes

  • Renamed hp-printer-default-login.yaml
  • Renamed moodle-filter-jmol-lfi.yaml and moodle-filter-jmol-xss.yaml
  • Renamed vbulletin-replacead-rce.yaml to CVE-2025-48828.yaml

New Features

  • Added templates for Brother Printers, NUUO NVR, and PhotoPrism
  • Added Kubernetes templates for exposing Docker sockets and pod creation permissions
  • Added templates for FBI Seized Nameserver and OpenShift OAuth Proxy
  • Added templates for TOTOLINK routers and Dahua 'GetClassValue' RCE

Full Release Notes

### New Templates Added: `67` | CVEs Added: `30` | First-time contributions: `9`

### 🔥 Release Highlights 🔥
- [CVE-2025-49132] Pterodactyl Panel - Remote Code Execution (@darses) [critical] 🔥
- [CVE-2025-30220] GeoServer WFS - XXE Processing Vulnerability (@iamnoooob, @pdresearch) [critical] 🔥
- [CVE-2024-3272] D-Link Network Attached Storage - Backdoor Account (@ritikchaddha) [critical] (kev) 🔥
- [CVE-2021-33045] Dahua IPC/VTH/VTO - Auth Bypass (@phantomowl) [critical] (kev) 🔥
- [CVE-2020-11984] Apache HTTP Server - RCE (@wofeiwo@80sec.com, @pszyszkowski, @pdresearch, @iamnoooob) [critical] 🔥
- [CVE-2020-0796] Microsoft SMBv3 - Remote Code Execution (@Yusuf Amr) [critical] (kev) 🔥
- [CVE-2020-0646] Microsoft .NET Framework - Remote Code Execution (@pszyszkowski) [critical] (kev) 🔥
- [CVE-2019-17564] Apache Dubbo 2.5.x-2.7.4 - Insecure Deserialization (@Khalid6468) [critical] 🔥
- [CVE-2019-0604] Microsoft SharePoint - RCE (@tree-chtsec, @pszyszkowski) [critical] (kev) 🔥
- [CVE-2018-19207] WP GDPR Compliance < 1.4.3 - Unauth Call Any Action or Update Any Option (@iamnoooob, @pdresearch) [critical]  🔥
- [CVE-2018-14933] NUUO NVRmini - RCE (@ritikchaddha) [critical] (kev) 🔥

---
## What's Changed

**Bounties Rewarded**  💰
* Anyscale Ray RCE (CVE-2023-48022, Issue #12451)  
* Microsoft SharePoint RCE (CVE-2019-0604, Issue #12340)  
* elFinder Command Injection (CVE-2019-9194, Issue #12288)  
* Microsoft SMBv3 RCE (CVE-2020-0796, Issue #12271)  
* Apache HTTP Server mod_proxy_uwsgi Info Disclosure & RCE (CVE-2020-11984, Issue #12266)  

**Bug Fixes**  
* Fixed typo in CVE-2020-13700 (#12509)  
* Corrected Microsoft Silverlight detection (#12492)  
* Fixed MCP templates (#12400)  
* Renamed CVE-2020-11984.yaml (#12469)  
* Renamed hp-printer-default-login.yaml (#12407)  

**False Negatives**  
* Improved conditional flow check for CVE-2025-29927 (#12480)  

**False Positives**  
* Fixed revoked-ssl-certificate false positives (#12409, #12445)  
* Reduced false positives in bagisto-csti.yaml (#12430)  
* Removed invalid CVE-2024-33559.yaml (#12437)  

**Enhancements**  
* Updated CVE-2019-0604.yaml (#12479)  
* Updated cisco-ise-admin-panel (#12477)  
* Updated and renamed moodle-filter-jmol-lfi.yaml & moodle-filter-jmol-xss.yaml (#12470)  
* Updated gogs-panel (#12466)  
* Updated and renamed vbulletin-replacead-rce.yaml to CVE-2025-48828.yaml (#12421)  
* Updated versa-director-login (#12422)  
* Updated veeam-backup-manager-login (#12399)  
* Updated misp-panel (#12390)  
* Updated privatebin-detect (#12354)  
* Updated mitel-micollab-panel (#12344)  
* Updated ActiveMQ default login & detection (#12329)  
* Updated Apache Airflow default login (#12328)  
* Updated apachespark-ui-exposed.yaml (#12289)  
* Updated tech-detect.yaml (#12274)


## Templates Added
- [CVE-2025-49132] Pterodactyl Panel - Remote Code Execution (@darses) [critical] 🔥
- [CVE-2025-47646] PSW Front-end Login & Registration 1.13 - Weak Password Recovery (@pussycat0x) [critical]
- [CVE-2025-47423] Personal Weather Station Dashboard 12 - Directory Traversal (@pussycat0x) [high]
- [CVE-2025-45985] Blink Router - Command Injection (@darses) [critical]
- [CVE-2025-45854] JEHC-BPM - Remote Code Execute (@ritikchaddha) [critical]
- [CVE-2025-44148] MailEnable Mail Service < v10 - Cross-Site Scripting (@ritikchaddha) [medium]
- [CVE-2025-34032] Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting (@madrobot, @ritikchaddha) [medium]
- [CVE-2025-34031] Moodle Jmol Filter 6.1 - Local File Inclusion (@madrobot) [high]
- [CVE-2025-30220] GeoServer WFS - XXE Processing Vulnerability (@iamnoooob, @pdresearch) [critical] 🔥
- [CVE-2025-5569] IdeaCMS <= 1.7 - SQL Injection (@ritikchaddha) [critical]
- [CVE-2025-5287] Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection (@CodeStuffBreakThings) [high]
- [CVE-2025-3415] Grafana - Exposes DingDing API Keys (@lucasribolli) [medium]
- [CVE-2024-51978] Brother Printers – Authentication Bypass via Default Admin Password (@iamnoooob, @pdresearch) [critical]
- [CVE-2024-51977] Brother MFC-L9570CDW - Information Disclosure (@DhiyaneshDK, @iamnoooob, @darses) [medium]
- [CVE-2024-4325] Gradio - Server-Side Request Forgery (@iamnoooob, @pdresearch) [high]
- [CVE-2024-3272] D-Link Network Attached Storage - Backdoor Account (@ritikchaddha) [critical] (kev) 🔥
- [CVE-2023-48022] Anyscale Ray - Remote Code Execution (@riteshs4hu) [critical]
- [CVE-2023-7116] WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection (@pussycat0x) [medium]
- [CVE-2021-33045] Dahua IPC/VTH/VTO - Authentication Bypass (@phantomowl) [critical] (kev) 🔥
- [CVE-2020-36333] ThemeGrill Demo Importer < 1.6.2 - Database Reset (@iamnoooob, @pdresearch) [critical]
- [CVE-2020-11984] Apache HTTP Server - Remote Code Execution (@wofeiwo@80sec.com, @pszyszkowski, @pdresearch, @iamnoooob) [critical] 🔥
- [CVE-2020-0796] Microsoft SMBv3 - Remote Code Execution (@Yusuf Amr) [critical] (kev) 🔥
- [CVE-2020-0646] Microsoft .NET Framework - Remote Code Execution (@pszyszkowski) [critical] (kev) 🔥
- [CVE-2019-17564] Apache Dubbo 2.5.x-2.7.4 - Insecure Deserialization (@Khalid6468) [critical] 🔥
- [CVE-2019-9194] elFinder <= 2.1.47 - Command Injection (@r00tuser111) [critical]
- [CVE-2019-7194] QNAP Photo Station < 6.0.3 - Remote Code Execution (@x-stp) [critical] (kev)
- [CVE-2019-0604] Microsoft SharePoint - Remote Code Execution (@tree-chtsec, @pszyszkowski) [critical] (kev) 🔥
- [CVE-2018-19207] WP GDPR Compliance < 1.4.3 - Unauthenticated Call Any Action or Update Any Option (@iamnoooob, @pdresearch) [critical]
- [CVE-2018-14933] NUUO NVRmini - Remote Command Execution (@ritikchaddha) [critical] (kev) 🔥
- [CVE-2018-11686] FlexPaper/FlowPaper 2.3.6 - Remote Code Execution (@iamnoooob, @pdresearch, @pszyszkowski) [critical]
- [kubernetes-exposing-docker-socket-hostpath] Kubernetes Exposing Host's Docker Socket (@dwisiswant0) [high]
- [k8s-role-pod-create] Roles that have pod create permissions (@domwhewell-sage) [medium]
- [fbi-seized-nameserver] FBI Seized Nameserver - Detect (@rxerium) [info]
- [activemq-artemis-default-login] Apache ActiveMQ Artemis Console Default Login (@pdteam) [high]
- [airflow-v3-default-login] Apache Airflow v3 Default Login (@pdteam) [high]
- [hp-printer-default-login] Hewlett Packard LaserJet Printer - Default Login (@JohnAsbjorn) [high]
- [ibm-security-verify-default-login] IBM Security Verify Access - Default Login (@johnk3r) [high]
- [nuuo-nvr-default-login] NUUO NVR - Default Login (@ritikchaddha) [high]
- [opensearch-dashboard-default-login] OpenSearch Dashboard - Default Login (@ritikchaddha) [high]
- [photoprism-default-login] PhotoPrism - Default Login (@ritikchaddha) [high]
- [beyondtrust-remotesupport-panel] BeyondTrust Remote Support Panel - Detect (@darses) [info]
- [brother-printer-panel] Brother Printer Panel - Detect (@pdteam) [info]
- [forgerock-ig-panel] ForgeRock IG Login/Welcome Page - Detect (@r3dg33k) [info]
- [ibm-security-verify-panel] IBM Security Verify Access Login - Panel (@johnk3r) [info]
- [motive-eim-panel] Motive eSIM Secure Connect Panel - Exposure Detection (@miguelse) [high]
- [myq-panel] MyQ Print Server Panel - Detect (@darses) [info]
- [opensearch-dashboard-panel] OpenSearch Dashboard Panel - Detect (@ritikchaddha) [info]
- [openshift-oauth-proxy-panel] OpenShift OAuth Proxy - Panel Detect (@r3dg33k) [info]
- [pterodactyl-panel] Pterodactyl game server - Panel (@darses) [info]
- [teleport-login-panel] Teleport Login Panel - Detect (@pdteam, @mahmoud0x00) [info]
- [tools4ever-ssrpm-panel] Tools4Ever Self-Service Reset Password Manager - Panel (@darses) [info]
- [windows-admin-center-panel] Windows Admin Center Panel - Detection (@darses) [info]
- [apache-kyuubi-config] Apache Kyuubi - Configuration Exposure (@icarot) [medium]
- [config-json-exposure-fuzz] Exposed JSON Configuration Files (@geeknik) [critical]
- [discord-invite-detect] Discord Invites for Users, Bots & Servers - Detect (@rxerium) [info]
- [totolink-installer] TOTOLINK Installer - Exposure (@ritikchaddha) [high]
- [opensearch-dashboard-unauth] OpenSearch Dashboard - Unauth Access (@ritikchaddha) [high]
- [photoprism-unauth] PhotoPrism - Unauth Access (@ritikchaddha) [high]
- [greatpages-takeover] GreatPages - Takeover Detection (@juliosmelo) [high]
- [apache-kyuubi-detect] Apache Kyuubi - Detect (@icarot) [info]
- [beyondtrust-remotesupport-version] BeyondTrust Remote Support Version - Detect (@missing0x00) [info]
- [cryptshare-detect] Pointsharp Cryptshare - Detect (@darses) [info]
- [mitel-version-detect] Mitel MiCollab Unified Communications Server (UCS) - Detect (@aushack) [info]
- [dahua-icc-getclassvalue-rce] Dahua 'GetClassValue' - Remote Code Execution (@ProjectDiscoveryAI) [critical]
- [totolink-boaform-rce] TOTOLink Router - Remote Command Execution (@ritikchaddha) [critical]
- [totolink-n150rt-password-exposure] TOTOLINK N150RT - Password Exposure (@ritikchaddha) [high]
- [ueditor-arbitrary-file-upload] UEditor - PHP Arbitrary File Upload (@ChiragArtani) [medium]

## New Contributors
* @nullenc0de made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12087
* @lucasribolli made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12410
* @riteshs4hu made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12429
* @aushack made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12368
* @pszyszkowski made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12452
* @cybermorgue made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12296
* @CodeStuffBreakThings made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12446
* @Yusuf-Amr made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12459
* @Khalid6468 made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/12462

**Full Changelog**: https://github.com/projectdiscovery/nuclei-templates/compare/v10.2.3...10.2.4