Vulnerability scanning, ranked by real-world exploitation.
Nuclei templates aggregated from multiple MIT sources, deduplicated, tested on the real engine, then enriched by joining CISA KEV and EPSS. You don’t scan 86,000 things at random: you scan what’s being exploited right now, first.
What we added recently
A living feed: here is the coverage added to it, dated.
- +86,373 templates
- +332 templates
Six bundles, one clear priority.
Only templates whose CVE is in the CISA KEV catalog (actively exploited), ranked by EPSS. Scan these first.
Unauthenticated exposures, misconfigurations, subdomain takeovers, default logins. What an attacker sees from outside.
VPNs, firewalls, gateways: Fortinet, Citrix, Pulse, F5, Exchange… The #1 ransomware entry point.
Cloud and API (REST, GraphQL, Swagger) misconfigurations that leak without a single CVE published.
Comprehensive coverage of WordPress core, plugins and themes, the broadest in the catalogue.
Templates targeting Jira, Confluence and Bitbucket, the most exposed collaboration stack.
Templates aggregated from multiple permissively-licensed open-source repos (MIT), deduplicated by id and by content, safety-filtered (code/headless/dast and fuzzing/brute-force removed) then validated on the real nuclei engine. Source provenance (commits) retained for license traceability.
Curation, not raw material.
Multiple MIT repos aggregated, deduplicated by id and by content hash, 1 best version per CVE, not 4 duplicates.
Every delivery passes `nuclei -validate` on the engine, broken templates are removed.
Dangerous or noisy templates (code, headless, dast, fuzzing, brute-force) are removed, scan without breaking or flooding.
Every CVE template is joined to CISA KEV (exploited) and EPSS (probability), a priority queue recomputed daily. Nobody else does this.
The feed is signed; you verify its integrity before every scan.
Permissive sources only (MIT); provenance and attribution retained in the pack, MSSP-redistributable.
How do I use it with nuclei?
The pack ships a `templates/` folder (the curated set) and a `bundles/` folder (KEV Rapid-Response, etc.). Run `nuclei -t templates/ -u https://target`, or point at a bundle to scan by priority. An `INDEX-priority.csv` ranks CVEs by KEV then EPSS.
Why pay, when Nuclei templates are free?
You’re not paying for the templates, you’re paying to not have to triage, dedupe, test and prioritize. The real value is the join with CISA KEV and EPSS, recomputed daily: it exists nowhere for free and turns 86,000 templates into a scan queue ordered by real-world exploitation.
What licenses, and can I resell / MSSP?
Permissive (MIT) sources only; unlicensed or copyleft repos are excluded. Provenance (commits) and attributions are retained in the pack. Redistributable to your clients with attribution.
Ready to scan what matters?
Annual subscription. Instant key. Cancel anytime.