| name | nuclei |
| description | Auth/lab ref: Template-based vulnerability and exposure scanner from ProjectDiscovery. |
| license | MIT |
| compatibility | Linux, Windows, macOS. |
| metadata | {"author":"AeonDave","version":"1.1"} |
Nuclei
Template-based scanner — 10,000+ community templates covering CVEs, misconfigs, exposures, default creds.
Quick Start
nuclei -update-templates
nuclei -u https://target.com
nuclei -l urls.txt -exclude-severity info -stats
Core Flags
| Flag | Description |
|---|
-u <url> | Single target URL |
-l <file> | File with list of URLs |
-im <mode> | Input mode: list, burp, jsonl, yaml, openapi, swagger |
-t <path> | Template file/directory/URL |
-tags <tags> | Run templates by tag (e.g., cve,rce,lfi) |
-as | Automatic technology-mapped scan |
-ni | Disable interactsh/OAST requests |
-id <id> | Run specific template by ID |
-severity <s> | Filter by severity: info,low,medium,high,critical |
-exclude-severity <s> | Exclude severity levels (alias: -es) |
-exclude-tags <tags> | Exclude tags (alias: -etags) |
-et <path> | Exclude template path |
-V <var=val> | Template variable override |
-nt | Run only new templates (since last update) |
-H <header> | Custom HTTP header |
-c <n> | Concurrent templates (default 25) |
-bs <n> | Bulk size (targets per template batch) |
-rl <n> | Rate limit req/sec (default 150) |
-timeout <n> | HTTP timeout (default 5s) |
-retries <n> | Retries on timeout |
-proxy <url> | HTTP/SOCKS5 proxy |
-o <file> | Output file |
-json | JSON output |
-jsonl, -j | JSON Lines output |
-silent | Print findings only |
-v | Verbose |
-stats | Show real-time stats |
-update-templates | Update community templates |
-tl | List all available templates |
Template Categories (Tags)
| Tag | Description |
|---|
cve | CVE-based exploits and detections |
panel | Admin/login panel detection |
exposure | Exposed files, tokens, secrets |
misconfig | Misconfigurations |
default-login | Default credentials |
takeover | Subdomain takeover |
tech | Technology fingerprinting |
xss | Cross-site scripting |
sqli | SQL injection |
ssrf | Server-side request forgery |
lfi | Local file inclusion |
rce | Remote code execution |
network | Network-level checks |
dns | DNS-level checks |
wordpress | WordPress-specific |
jira | Jira-specific |
gitlab | GitLab-specific |
Common Workflows
nuclei -l hosts.txt -tags tech,panel -severity info,low -silent
nuclei -l hosts.txt -tags cve -severity critical,high -o cve_findings.jsonl -jsonl
nuclei -l targets.txt -as -severity critical,high -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -silent -j -o nuclei.jsonl
nuclei -l targets.txt -as -severity critical,high -ni -stats -rl 30 -c 10 -bs 10 -timeout 10 -retries 1 -j -o nuclei_no_oast.jsonl
nuclei -l hosts.txt -tags panel,default-login -severity medium,high,critical
nuclei -l urls.txt -tags exposure -silent
nuclei -l subs.txt -tags takeover
nuclei -l urls.txt -tags xss,sqli,ssrf,lfi -severity medium,high,critical
nuclei -u https://target.com -tags wordpress -severity medium,high,critical
nuclei -l hosts.txt -exclude-severity info -o findings.jsonl -jsonl -stats
nuclei -l hosts.txt -nt -severity high,critical
subfinder -d target.com -silent | \
httpx -silent | \
nuclei -tags cve,panel,exposure,misconfig -severity high,critical
nuclei -u https://target.com -proxy http://127.0.0.1:8080
Template Management
nuclei -update-templates
nuclei -tl
nuclei -tl -tags cve | head -20
nuclei -u https://target.com -t cves/2021/CVE-2021-44228.yaml
nuclei -l hosts.txt -t ~/custom-templates/
nuclei -u https://target.com -t custom.yaml -V "target_path=/admin"
Resources
| File | When to load |
|---|
references/templates.md | Template structure, custom writing, matcher/extractor types, output parsing, rate tuning |