Nuclei POC 精选分析 - 2026-10-01
📊 智能筛选概况
- 发现变更: 13 个模板更新
- 精选分析: 11 个高价值 POC
- 智能跳过: 2 个低优先级模板
- 高风险漏洞: 6 个
- 主要类别: CVE漏洞(6), 其他(5)
💡 智能筛选说明: 系统自动优先分析 CVE 漏洞、高危漏洞和新增模板,跳过低价值的技术识别类模板,确保高效利用 API 资源。
严重程度分布
- 🟠 高危: 6 个
- ⚪ 信息: 5 个
🔍 重点漏洞分析
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
React Server Components - Denial of Service
- 漏洞ID:
CVE-2025-55184 - CVE:
CVE-2025-55184(2025) - 严重程度: 🟠 HIGH
- 风险等级: 极高风险 (5/5)
- 影响资产: 未知
- 预估影响: 数千个
- EPSS: 0.66882 (percentile 0.99272) @ 2026-09-29
描述: React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.
攻击向量: 网络扫描
CVE编号: CVE-2025-55184
参考链接:
📋 完整模板列表
| 模板名称 | 严重程度 | 类别 | 影响资产 | EPSS | 风险评分 |
|---|---|---|---|---|---|
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| React Server Components - Denial of Service | 🟠 high | CVE漏洞 | 通用 | 0.6688 | 5/5 |
| Secomea GateManager Panel - Detect | ⚪ info | 其他 | 管理面板 | - | 1/5 |
| OutBack Power Mate3s Gateway - Detect | ⚪ info | 其他 | 管理面板 | - | 1/5 |
| OutBack Power Mate3s Gateway - Detect | ⚪ info | 其他 | 管理面板 | - | 1/5 |
| Secomea GateManager Panel - Detect | ⚪ info | 其他 | 管理面板 | - | 1/5 |
| Secomea GateManager Panel - Detect | ⚪ info | 其他 | 管理面板 | - | 1/5 |
🛡️ 安全建议
🚨 发现高风险漏洞,建议立即扫描相关资产 🔍 关注新发布的 CVE 漏洞,及时更新补丁
🔧 扫描建议
建议使用以下 Nuclei 命令进行扫描:
# 扫描高危漏洞
nuclei -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -u target-url
# 扫描所有今日新增模板
nuclei -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/cves/2025/CVE-2025-55184.yaml -t http/exposed-panels/secomea-gatemanager-panel.yaml -t http/exposed-panels/outback-power-detect.yaml -t http/exposed-panels/outback-power-detect.yaml -t http/exposed-panels/secomea-gatemanager-panel.yaml -t http/exposed-panels/secomea-gatemanager-panel.yaml -u target-url
本报告基于 Nuclei 模板库自动生成,数据来源:ProjectDiscovery/nuclei-templates
扫描建议仅供参考,请在授权环境下进行安全测试