# projectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Repository: https://github.com/projectdiscovery/nuclei-templates
Canonical: https://ross.abutalabs.com/products/nuclei-templates
Homepage: https://github.com/projectdiscovery/nuclei
Language: JavaScript
License: MIT
License Family: permissive
Topics: nuclei-templates, nuclei, bugbounty, security, nuclei-checks, exploits, exploit-development, vulnerability-detection, fingerprint, hacktoberfest
Last push: 2026-08-26T13:08:45+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 2342, "days_push": 7, "days_rel": 9, "gap_med": 17, "n_releases_24m": 40}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 12849, forks 3630 (observed 2026-08-28T04:10:59.921632+00:00)

## What it is
A community-curated collection of YAML-based templates for the Nuclei vulnerability scanner, used to detect security vulnerabilities, misconfigurations, and exposed services across applications, APIs, networks, and DNS. It includes thousands of checks with coverage of CISA and VulnCheck Known Exploited Vulnerabilities (KEV) catalogs.

## Use cases
- scan my infrastructure for known exploited vulnerabilities
- find CVEs in web applications and APIs
- run bug bounty reconnaissance checks
- detect exposed admin panels and misconfigurations
- check assets against CISA KEV catalog
- fingerprint technologies on target hosts
- build custom detection templates for new CVEs

## When to choose
- you already use or plan to use the Nuclei scanner engine
- you need community-maintained, frequently updated vulnerability detection signatures
- you want KEV-based prioritized scanning of actively exploited CVEs
- you contribute or customize detection checks via a simple YAML DSL

## When to avoid
- you need a standalone scanner - this is only a template dataset, not the scanning engine
- you need deep authenticated dynamic application security testing rather than signature-based checks
- your environment forbids running offensive security tooling

## Facets
- artifact type: dataset
- maturity: active
- function: security, vulnerability-scanning, penetration-testing
- domain: security, penetration-testing, developer-tools
- platform: cross-platform, cli
- tags: nuclei, vulnerability-detection, bugbounty, yaml-templates, kev, exploits, fingerprinting, community-curated

## Member repositories
- projectdiscovery/nuclei-templates (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:59.921632+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:44.638879+00:00, confidence not recorded.
  - readme: https://github.com/projectdiscovery/nuclei-templates (fetched 2026-08-28T04:10:59.921632+00:00, sha f44b702a6b8d)
  - homepage: https://github.com/projectdiscovery/nuclei (fetched 2026-08-29T08:09:59.416173+00:00, sha 806267c9f850)
- Data as of 2026-08-30T08:39:29.467469+00:00.
