Project Discovery maintains a narrowly focused set of reconnaissance and security-testing tools, with its vulnerability footprint concentrated in products like Nuclei and Interactsh that are widely used by penetration testers and security researchers. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through injection and access-control weakness classes—code injection, OS command injection, path traversal, and improper authorization—that are characteristic of tools designed to execute user-supplied payloads and interact with untrusted network services. Defenders deploying these tools should treat them as high-value targets for compromise and restrict their execution context accordingly; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectdiscovery over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5262CRITICAL Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and | Jun 5, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-43405HIGH Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification | Sep 4, 2024 | 7.8 | 26 | NO | NO |
CVE-2026-41646MEDIUM Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaS | May 8, 2026 | 5.5 | 24 | NO | NO |
CVE-2026-41645MEDIUM Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it po | May 8, 2026 | 5.3 | 24 | NO | NO |
CVE-2026-41282HIGH ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configurat | Apr 20, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-27920HIGH projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the | Mar 15, 2024 | 7.4 | 23 | NO | NO |
CVE-2023-37896HIGH Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This is | Aug 4, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36474MEDIUM Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for | Jun 28, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectdiscovery.
Media articles that mention a CVE ID that affects a product developed by Projectdiscovery — matched by CVE ID, not by vendor name.