
Community-Powered Vulnerability Scanner
Nuclei is an open-source, template-based vulnerability scanner by ProjectDiscovery that uses community-powered YAML templates to identify security vulnerabilities across applications, APIs, cloud infrastructure, and networks. With 12,000+ templates maintained by 900+ contributors and a single Go binary, it delivers near-zero false positives and integrates seamlessly into CI/CD pipelines.
YAML templates define security checks across HTTP, DNS, TCP, SSL, WebSocket, and headless browser protocols
Maintained by 900+ contributors covering CVEs, misconfigurations, default credentials, and exposures
Tests web apps, APIs, DNS, network services, SSL/TLS, and cloud infrastructure from a single tool
Single Go binary with JSON and SARIF output for automated security checks in pipelines
Generate vulnerability detection templates from natural language descriptions
Template-driven matching against specific conditions produces highly accurate results
5-hour detection time for critical CVEs compared to 2-5 days for legacy scanners
Automatically scan every build and deployment for known CVEs and misconfigurations before production
Map external assets and continuously scan for new exposures across domains and subdomains
Scan AWS, GCP, and Azure for misconfigurations and insecure default settings
Bug bounty hunters rapidly triage large target lists identifying known vulnerabilities
Best open-source vulnerability scanner for small teams — 12,000+ detection templates, near-zero false positives, and CI/CD-ready output make it the most practical free alternative to commercial scanners.
The essential bug bounty scanner — fast, accurate, free, and backed by the largest community-maintained vulnerability template library
Web-based interface for managing scans, assets, and results with team collaboration
Run templated checks against server configurations and security headers for compliance baselines

The fastest AI code editor — built in Rust for speed and collaboration