Detect infrastructure vulnerabilities in real time with customizable templates and low false‑positive rates across multiple protocols.

ProjectDiscovery Nuclei is an open-source vulnerability scanner that identifies exploitable vulnerabilities by using a template-based approach to simulate real-world attack conditions. The software is primarily deployed as a standalone command-line interface tool, though it can be integrated into broader security workflows to monitor infrastructure for flaws.
Users employ the tool to conduct comprehensive vulnerability assessments, detect subdomain takeovers, and perform dynamic application security testing. It is designed to be integrated into CI/CD pipelines for continuous vulnerability detection and regression testing, ensuring that new deployments do not introduce known security regressions. The tool supports a wide range of input formats for target lists, including standard text files, Burp Suite exports, JSONL, and OpenAPI specifications.
The architecture relies on a community-driven template library, where thousands of security professionals contribute YAML files to track trending vulnerabilities. This allows the scanner to adapt quickly to new CVEs without requiring core software updates. The engine is designed to reduce false positives by simulating the exact steps required to verify a vulnerability in a live environment. It is built specifically for pentesters, security teams, and enterprises who need to map their attack surface and verify the presence of specific flaws across large sets of targets.
ProjectDiscovery is a high-performance tool for security automation and vulnerability management.
A self-hosted personal AI assistant that integrates with multiple messaging apps to perform tasks and automate workflows.
Automate workflows by connecting hundreds of applications through a visual interface with support for custom code.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.