Nuclei just crossed 30,000 stars.
Thank you to everyone who starred it, wrote a template, filed an issue, or shipped a fix. This one belongs to the community.
Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963)
I reproduced the bug locally; interesting one (power of LLM, I think)
github.com/keycloak/keycl…
We built Neo for all security teams, big or small.
→ The two-person team with a long backlog.
→ The startup shipping fast with no pentest budget.
→ The enterprise scanning thousands of assets with only a few people to cover them.
Try it today → neo.projectdiscovery.io/sign-up
Finding a potential XSS is only the first step.
Neo automatically :
-> opens a real browser
-> executes the payload
-> confirms JavaScript execution
-> captures the alert screenshot as evidence
-> Introducing Neo Browser Computer Use -- an autonomous PoC collector.
Finding XSS
You can now run multiple cloud browsers inside Neo at the same time.
-> Spin up a few sessions, select the ones you care about, and send one prompt.
-> Neo can work across all of them
open pages, click through flows, and check that things like login and signup actually work.